CVE-2026-11404

Executive Summary

Cesanta Mongoose <7.22 vulnerable to an out‑of‑bounds read via a crafted TLS ClientHello session_id_len byte, allowing a remote unauthenticated attacker to crash HTTPS, MQTTS, or WSS services that use MG_TLS_BUILTIN.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2026-07-09T16:16:34.640 - Last Modified: 2026-08-29T14:16:37.450

Original Description: Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single crafted ClientHello with an oversized session id length to read past the receive buffer, crashing any HTTPS, MQTTS, or WSS service built on MG_TLS_BUILTIN.

"Life is not measured by the breaths you take, but by its breathtaking moments."

— Michael Vance
Source: NVD