Remote Code Execution Risk in Mongoose Web Server Prior to Version 7.22
CVE-2026-73258

6.5MEDIUM

Key Information:

Vendor

Cesanta

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-73258?

The Mongoose web server, an embedded web solution provided by Cesanta, is subject to a vulnerability that allows remote attackers to exploit multipart input processed by the mg_http_next_multipart function. Specifically, prior to version 7.22, this issue arises from an incorrect evaluation of conditions that manage character sequences, resulting in truncated headers, file names, or boundaries. As a consequence, an application may accept harmful content under misleading Content-Type values, creating an avenue for potential remote code execution. This vulnerability has been addressed in version 7.22.

Affected Version(s)

mongoose < 7.22

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.