CVE-2026-73257
CVE-2026-73257 is a critical-severity vulnerability in Cesanta Mongoose with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-444.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- EPSS exploit prediction: 1% (50th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-444
- Affected product: Cesanta Mongoose
- Published:
- Last modified:
Description
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and prioritize chunked encoding, while a Content-Length-preferring reverse proxy can use a different request boundary. This CL.TE desynchronization can inject requests that access or modify resources in another user context. This issue is fixed in version 7.22.
Frequently asked questions
- What is CVE-2026-73257?
- Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and prioritize chunked encoding, while a Content-Length-preferring reverse proxy can use a different request boundary. This CL.TE desynchronization can inject requests that access or modify resources in another user context. This issue is fixed in version 7.22.
- How severe is CVE-2026-73257?
- CVE-2026-73257 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-73257 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (50th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-73257?
- CVE-2026-73257 affects Cesanta Mongoose. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-73257?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-73257 published?
- CVE-2026-73257 was published on 2026-08-20 and last updated on 2026-09-29.
References
- https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71
- https://github.com/cesanta/mongoose/pull/3611
- https://github.com/cesanta/mongoose/releases/tag/7.22
- https://github.com/cesanta/mongoose/security/advisories/GHSA-5wfq-r6mr-wqp6
Affected products (1)
- cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:*
More vulnerabilities in Cesanta Mongoose
- CVE-2022-25299 — Critical (CVSS 9.8): This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using…
- CVE-2020-25756 — Critical (CVSS 9.8): A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of…
- CVE-2019-19307 — Critical (CVSS 9.8): An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS…
- CVE-2019-12951 — Critical (CVSS 9.8): An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based…
- CVE-2018-20356 — Critical (CVSS 9.8): An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in…
- CVE-2018-20355 — Critical (CVSS 9.8): An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in…
All CVEs affecting Cesanta Mongoose →
Other CWE-444 (HTTP Request/Response Smuggling) vulnerabilities
- CVE-2026-88773 — Critical (CVSS 10.0): Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC…
- CVE-2026-58150 — Critical (CVSS 10.0): Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request…
- CVE-2026-57834 — Critical (CVSS 10.0): Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic…
- CVE-2025-1867 — Critical (CVSS 10.0): Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in ithewei libhv allows…
- CVE-2022-22536 — Critical (CVSS 10.0): SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53…
- CVE-2018-3907 — Critical (CVSS 10.0): An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub…
Browse all CWE-444 (HTTP Request/Response Smuggling) vulnerabilities →