CVE-2026-73256
🟠 Łataj w tym tygodniu
Błąd w Mongoose umożliwia atakującemu zdalne oszustwo żądań i nieautoryzowany dostęp.
CVSS
9.1
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)
Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests hm.proto.len with an impossible greater-than-eight condition even though mg_http_parse() requires an eight-byte protocol string, so is_http_1_0 is never set. Mongoose consequently processes chunked encoding that an HTTP/1.0 proxy can ignore, enabling request smuggling and unauthorized access or state changes. This issue is fixed in version 7.22.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-08-20 18:16:46 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-21 22:16:44 UTC |
Referencje
- https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71 (security-advisories@github.com)
- https://github.com/cesanta/mongoose/pull/3611 (security-advisories@github.com)
- https://github.com/cesanta/mongoose/releases/tag/7.22 (security-advisories@github.com)
- https://github.com/cesanta/mongoose/security/advisories/GHSA-mgp5-rjrv-h5j3 (security-advisories@github.com)