CVE-2018-20352: Cesanta Mongoose Embedded Web Server Library

High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

Affected products

  • Cesanta Mongoose Embedded Web Server Library: up to and including 6.13

Published 2019-06-10. Last modified 2026-06-17.