CVE-2025-51495: Integer Overflow
An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51495?
CVE-2025-51495 is classified as a critical severity vulnerability due to its potential to crash applications.
How do I fix CVE-2025-51495?
To fix CVE-2025-51495, update Mongoose to a version higher than 7.17 or apply patches provided by the vendor.
What versions of Mongoose are affected by CVE-2025-51495?
CVE-2025-51495 affects Mongoose versions 7.5 through 7.17.
What type of attack is associated with CVE-2025-51495?
CVE-2025-51495 is associated with an integer overflow attack that can lead to application crashes.
Can CVE-2025-51495 lead to a buffer overflow?
Yes, if downstream vendors integrate Mongoose improperly, CVE-2025-51495 may lead to a buffer overflow.