Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-101003 is a stack-based buffer overflow vulnerability in Cesanta Mongoose versions 7.0 through 7.21. It affects the MQTT Broker component, specifically the function 'fn' in the file tutorials/mqtt/mqtt-server/main.c. The vulnerability can be exploited remotely without authentication or user interaction. A public exploit is available. Upgrading to version 7.22 resolves this issue. Join the discussion | CVE Database V5 | 09/28/2026, 05:30:14 UTC Added: 09/28/2026, 05:48:21 UTC |
Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_cert_san() and mg_tls_verify_cert_cn() functions in src/tls_builtin.c call mg_match(), whose wildcard can cross DNS label boundaries, so a pattern such as *.example.com can match foo.bar.example.com. The resulting hostname verification bypass permits interception and modification of TLS traffic. This issue is fixed in version 7.22. Join the discussion | CVE Database V5 | 08/20/2026, 17:41:02 UTC Added: 08/20/2026, 17:52:46 UTC |
0 CVE-2026-73255 is a path traversal vulnerability in the cesanta mongoose embedded web server and network library. Versions prior to 7.22 allow an attacker who can control an SSI-enabled file to include directory traversal sequences in #include directives. This leads to disclosure of files readable by the Mongoose process due to improper sanitization of the file path. The issue is fixed in version 7.22. Join the discussion | CVE Database V5 | 08/20/2026, 17:40:02 UTC Added: 08/20/2026, 17:52:46 UTC |
0 Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI into the title and h1 elements without HTML entity encoding. The resulting reflected cross-site scripting executes in the Mongoose origin and can expose session data or perform actions as the victim. This issue is fixed in version 7.22. Join the discussion | CVE Database V5 | 08/20/2026, 17:39:16 UTC Added: 08/20/2026, 17:52:46 UTC |
0 Mongoose, an embedded web server and network library, has a critical HTTP request smuggling vulnerability (CVE-2026-73256) affecting versions prior to 7.22. The flaw arises from inconsistent handling of HTTP/1.0 requests with Transfer-Encoding: chunked headers, allowing remote unauthenticated attackers to bypass proxy protections. This can lead to unauthorized access or state changes. The issue is fixed in version 7.22. Join the discussion | CVE Database V5 | 08/20/2026, 17:37:54 UTC Added: 08/20/2026, 17:52:46 UTC |
0 CVE-2026-73254 is a stored cross-site scripting (XSS) vulnerability in the cesanta mongoose embedded web server and network library. The flaw exists in versions prior to 7.22 when directory listing is enabled (MG_ENABLE_DIRLIST). An attacker who can create a file with an HTML payload in its filename can cause the server to inject this raw filename into the HTML link text without proper neutralization, leading to script execution in the user's browser. This can expose session data or allow actions to be performed as the victim. The issue is fixed in version 7.22. Join the discussion | CVE Database V5 | 08/20/2026, 17:37:17 UTC Added: 08/20/2026, 17:52:46 UTC |
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s[b + 1], and s[h2] and s[h2 + 1], use an incorrect AND condition and stop when either character resembles part of a CRLF terminator. This truncates headers, filenames, or boundaries and can cause an application to accept dangerous content after seeing a misleading Content-Type value. This issue is fixed in version 7.22. Join the discussion | CVE Database V5 | 08/20/2026, 17:36:39 UTC Added: 08/20/2026, 17:52:46 UTC |
Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function stores the bundle in tls->ca_bundle_der while tls->ca_der.len remains zero, and mg_tls_recv_cert() uses tls_bundle_find() to accept a Common Name match without calling mg_tls_verify_cert_signature(). A forged self-signed certificate can therefore satisfy hostname and CertificateVerify checks and enable interception, credential disclosure, traffic modification, and malicious responses. This issue is fixed in version 7.23. Join the discussion | CVE Database V5 | 08/20/2026, 17:34:50 UTC Added: 08/20/2026, 17:52:46 UTC |
0 Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and prioritize chunked encoding, while a Content-Length-preferring reverse proxy can use a different request boundary. This CL.TE desynchronization can inject requests that access or modify resources in another user context. This issue is fixed in version 7.22. Join the discussion | CVE Database V5 | 08/20/2026, 17:30:58 UTC Added: 08/20/2026, 17:52:46 UTC |
0 Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single crafted ClientHello with an oversized session id length to read past the receive buffer, crashing any HTTPS, MQTTS, or WSS service built on MG_TLS_BUILTIN. Join the discussion | CVE Database V5 | 07/09/2026, 15:13:40 UTC Added: 07/09/2026, 15:33:27 UTC |
Showing 1 to 10 of 17 results