CVE-2026-73256: CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in cesanta mongoose
Description
Mongoose, an embedded web server and network library, has a critical HTTP request smuggling vulnerability (CVE-2026-73256) affecting versions prior to 7.22. The flaw arises from inconsistent handling of HTTP/1.0 requests with Transfer-Encoding: chunked headers, allowing remote unauthenticated attackers to bypass proxy protections. This can lead to unauthorized access or state changes. The issue is fixed in version 7.22.
CVSS v3.1
Score 9.1critical
Affected software
cesanta
mongoose
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-73256 is an HTTP request smuggling vulnerability in cesanta mongoose versions before 7.22. The vulnerability stems from the http_cb() function in src/http.c incorrectly testing the HTTP protocol length, causing the is_http_1_0 flag never to be set. As a result, mongoose processes chunked Transfer-Encoding headers in HTTP/1.0 reverse-proxy deployments, which can be ignored by the proxy, enabling request smuggling attacks. This allows remote unauthenticated attackers to perform unauthorized actions or access sensitive state. The vulnerability is addressed in mongoose version 7.22.
Potential Impact
An attacker can exploit this vulnerability remotely without authentication to perform HTTP request smuggling against HTTP/1.0 reverse-proxy deployments using mongoose. This can lead to unauthorized access or unauthorized state changes in the affected system. The CVSS v3.1 score is 9.1 (critical), indicating high confidentiality and integrity impact with no availability impact.
Mitigation Recommendations
Upgrade mongoose to version 7.22 or later, where this vulnerability is fixed. No other mitigation or workaround is indicated in the available data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-11T17:18:01.598Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a873eeeacd9273b49f2b5e6
Added to database: 08/20/2026, 17:52:46 UTC
Last enriched: 09/10/2026, 23:17:16 UTC
Last updated: 10/04/2026, 18:53:18 UTC
Views: 75
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.