cesanta.mongoose is vulnerable to Out-of-bounds Read
75
High Risk
The built-in TLS stack accepts a record whose decrypted size equals the AEAD tag size, leaving no room for the required content-type byte. The remaining-length computation then underflows to a maximum value that persists, causing later handshake steps to treat stale buffer bytes as a trusted, effectively unbounded message. An unauthenticated peer can trigger an attacker-influenced heap over-read and crash the service before authentication. The fix requires records to exceed the tag size.
You are affected if you are using a version that falls within the vulnerable range and you use the built-in TLS backend (MG_TLS_BUILTIN).
cesanta.mongoose is vulnerable to Out-of-bounds Read in versions 7.13 - 7.22.
Upgrade the cesanta.mongoose library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant