CVE-2021-26528: Critical severity mongoose os vulnerability
Published Feb 8, 2021
·Updated
The mghttpservefile function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after exhausting memory pool.
Affected Software
1 affected component
Cesanta Mongoose=7.0
Event History
Feb 8, 2021
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-26528.
2
What is the severity of CVE-2021-26528?
The severity of CVE-2021-26528 is critical with a CVSS score of 9.1.
3
What is the affected software version?
The affected software version is Cesanta Mongoose 7.0.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-787.
5
Is there a reference to learn more about this vulnerability?
Yes, you can learn more about this vulnerability at the following link: [GitHub Issue #1201](https://github.com/cesanta/mongoose/issues/1201).