Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cesanta
Cesanta mongoose |
|
| Vendors & Products |
Cesanta
Cesanta mongoose |
Thu, 20 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s[b + 1], and s[h2] and s[h2 + 1], use an incorrect AND condition and stop when either character resembles part of a CRLF terminator. This truncates headers, filenames, or boundaries and can cause an application to accept dangerous content after seeing a misleading Content-Type value. This issue is fixed in version 7.22. | |
| Title | Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart | |
| Weaknesses | CWE-697 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T18:32:51.938Z
Reserved: 2026-08-11T17:18:01.598Z
Link: CVE-2026-73258
No data.
Status : Received
Published: 2026-08-20T18:16:47.323
Modified: 2026-08-20T18:16:47.323
Link: CVE-2026-73258
No data.
OpenCVE Enrichment
Updated: 2026-08-20T18:30:03Z