ZeroHour

CVE-2021-26530

PoC
CVSS 3.1
9.1 critical
EPSS
1%p72
Published
()
Modified
Description

The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.

Vendors
cesanta
Products
mongoose
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.