CVE-2020-25756: Cesanta Mongoose

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking. A crafted HTTP header can exploit this bug. NOTE: a committer has stated "this will not happen in practice.

Affected products

  • Cesanta Mongoose: version 6.18 only

Published 2020-09-18. Last modified 2026-06-17.