CVE-2024-42385: Cesanta Mongoose

High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

Affected products

  • Cesanta Mongoose: up to and including 7.14

Published 2024-11-18. Last modified 2026-09-08.