See how valenok compares to other vendors in security performance
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.
Stack-based buffer overflow in the (1) putdir function in mongoose.c in Mongoose 3.0, (2) putdir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) shttpdputdir function in iodir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.