CVE-2026-11404Patch

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single crafted ClientHello with an oversized session id length to read past the receive buffer, crashing any HTTPS, MQTTS, or WSS service built on MG_TLS_BUILTIN.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Cesanta Mongoose built-in TLS ClientHello OOB read DoS (CVE-2026-11404) Cesanta Mongoose before 7.22 is vulnerable to an out-of-bounds read in the built-in TLS server receive path, specifically mg_tls_server_recv_hello() when parsing a TLS ClientHello. The root cause is improper input validation: an attacker-controlled session_id_len is used as a buffer index without checking it against the actual received data length. A remote, unauthenticated attacker can exploit this by sending a crafted TLS ClientHello with an oversized session ID length to force reads past the end of the receive buffer. Impact is a reliable crash/denial of service of HTTPS, MQTTS, or WSS endpoints using MG_TLS_BUILTIN, potentially taking internet-facing services offline. 👉 Affected: Cesanta Mongoose < 7.22 (MG_TLS_BUILTIN) | Upgrade to 7.22

    Post summary

    The CVE-2026-11404 vulnerability causes a reliable DoS via an OOB read in Cesanta Mongoose; upgrading to 7.22 mitigates the risk.

    0000085
    246 followersView on X

Explore more