cesanta.mongoose is vulnerable to Out-of-bounds Read
75
High Risk
The built-in TLS server reads the session id length byte from a ClientHello and uses it as a buffer index without checking it against the amount of received data. A single crafted ClientHello with an oversized session id length drives an out-of-bounds read past the receive buffer. This can crash any HTTPS, MQTTS, or WSS service using the built-in TLS backend, and is reachable before authentication. The fix validates the session id length before use.
You are affected if you are using a version that falls within the vulnerable range and you use the built-in TLS backend (MG_TLS_BUILTIN) to terminate TLS.
cesanta.mongoose is vulnerable to Out-of-bounds Read in versions 7.13 - 7.21.
Upgrade the cesanta.mongoose library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant