CVE-2024-42386: Cesanta Mongoose

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Affected products

  • Cesanta Mongoose: up to and including 7.14

Published 2024-11-18. Last modified 2026-09-08.