
🚨 HIGH - Cesanta Mongoose built-in TLS ClientHello OOB read DoS (CVE-2026-11404) Cesanta Mongoose before 7.22 is vulnerable to an out-of-bounds read in the built-in TLS server receive path, specifically mg_tls_server_recv_hello() when parsing a TLS ClientHello. The root cause is improper input validation: an attacker-controlled session_id_len is used as a buffer index without checking it against the actual received data length. A remote, unauthenticated attacker can exploit this by sending a crafted TLS ClientHello with an oversized session ID length to force reads past the end of the receive buffer. Impact is a reliable crash/denial of service of HTTPS, MQTTS, or WSS endpoints using MG_TLS_BUILTIN, potentially taking internet-facing services offline. 👉 Affected: Cesanta Mongoose < 7.22 (MG_TLS_BUILTIN) | Upgrade to 7.22
Post summary
The CVE-2026-11404 vulnerability causes a reliable DoS via an OOB read in Cesanta Mongoose; upgrading to 7.22 mitigates the risk.
