Directory Traversal Vulnerability in Mongoose Embedded Web Server
CVE-2026-73255

6.5MEDIUM

Key Information:

Vendor

Cesanta

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-73255?

Mongoose, an embedded web server, contains a vulnerability allowing attackers to exploit server-side includes (SSI) by controlling an SSI-enabled file. This vulnerability enables attackers to embed directory traversal sequences in include directives, potentially disclosing sensitive files that the Mongoose process can read. The issue arises from a failure to validate the filesystem path before processing, which has been mitigated in version 7.22.

Affected Version(s)

mongoose < 7.22

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.