CVE-2024-42385

Executive Summary

Cesanta Mongoose Web Server v7.14 fails to properly neutralize delimiters in PEM certificates, allowing an attacker to supply a certificate with unexpected characters that triggers an out‑of‑bounds memory write. This flaw can lead to crashes or potential remote code execution, compromising the integrity and availability of services using the affected server.


Authoritative CVE Metadata - CVSS Base Score: 4.0 (MEDIUM) - Published: 2024-11-18T10:15:07.187 - Last Modified: 2026-09-08T09:17:17.737

Original Description: Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

"Make the most of yourself for that is all there is of you."

— Ralph Emerson
Source: NVD