CVE-2026-73256

🟠 Łataj w tym tygodniu

Błąd w Mongoose umożliwia atakującemu zdalne oszustwo żądań i nieautoryzowany dostęp.

CVSS
9.1
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests hm.proto.len with an impossible greater-than-eight condition even though mg_http_parse() requires an eight-byte protocol string, so is_http_1_0 is never set. Mongoose consequently processes chunked encoding that an HTTP/1.0 proxy can ignore, enabling request smuggling and unauthorized access or state changes. This issue is fixed in version 7.22.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-08-20 18:16:46 UTC
Ostatnia modyfikacja (NVD)2026-08-21 22:16:44 UTC
Referencje