Mongoose, an embedded web server and network library, is vulnerable to request smuggling in HTTP/1.0 reverse-proxy deployments prior to version 7.22. The issue arises from improper handling of Transfer-Encoding: chunked requests with conflicting framing, allowing remote unauthenticated attackers to potentially access or change system state. Organizations should review their deployments, especially those u [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T18:16:46.113Z and has not been modified since then. Mongoose is an embedded web server and network library with a stored cross-site scripting vulnerability prior to version 7.22. An attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user [truncated]
CVE-2026-11404 is a high-severity vulnerability in Cesanta Mongoose, a popular embedded web server. The vulnerability exists in the built-in TLS server function mg_tls_server_recv_hello(), which does not properly validate the session_id_len byte from a TLS ClientHello. This allows a remote, unauthenticated attacker to send a crafted ClientHello with an oversized session id length, causing the server to re [truncated]