Remote Code Execution Risk in Mongoose Web Server Prior to Version 7.22
CVE-2026-73258
6.5MEDIUM
What is CVE-2026-73258?
The Mongoose web server, an embedded web solution provided by Cesanta, is subject to a vulnerability that allows remote attackers to exploit multipart input processed by the mg_http_next_multipart function. Specifically, prior to version 7.22, this issue arises from an incorrect evaluation of conditions that manage character sequences, resulting in truncated headers, file names, or boundaries. As a consequence, an application may accept harmful content under misleading Content-Type values, creating an avenue for potential remote code execution. This vulnerability has been addressed in version 7.22.
Affected Version(s)
mongoose < 7.22
