CVE-2025-51495: Cesanta Mongoose
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.
Affected products
- Cesanta Mongoose: from 7.5, up to and including 7.17
Published 2025-09-29. Last modified 2026-06-17.