PT-2026-56811 · Cesanta · Mongoose

·

CVE-2026-11404

·

Published

2026-07-09

·

Updated

2026-08-29

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Cesanta Mongoose versions prior to 7.22
Description An out-of-bounds read exists in the built-in TLS server function mg tls server recv hello(). The issue occurs because the function uses an attacker-controlled session id len byte from a TLS ClientHello as a buffer index without validating it against the length of the received data. A remote, unauthenticated attacker can send a crafted ClientHello with an oversized session ID length to read past the receive buffer, resulting in a crash and denial of service for HTTPS, MQTTS, or WSS services utilizing MG TLS BUILTIN.
Recommendations Update to version 7.22.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11404
JLSEC-2026-1257

Affected Products

Mongoose