CVE-2026-73258: Cesanta Mongoose
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s[b + 1], and s[h2] and s[h2 + 1], use an incorrect AND condition and stop when either character resembles part of a CRLF terminator. This truncates headers, filenames, or boundaries and can cause an application to accept dangerous content after seeing a misleading Content-Type value. This issue is fixed in version 7.22.
Affected products
- Cesanta Mongoose: before 7.22 (fixed in 7.22)
Published 2026-08-20. Last modified 2026-09-29.