
Mongoose network library <= 7.20 CVE-2026-5244 - mg_tls_recv_cert pubkey heap-based overflow (exploitable) CVE-2026-5245 - mDNS Record stack-based overflow (exploitable) CVE-2026-5246 - authorization bypass via P-384 Public Key (trivially exploitable) Fun ride. https://t.co/KUBymdWrJF
Post summary
The tweet announces three CVEs (CVE‑2026‑5244, CVE‑2026‑5245, CVE‑2026‑5246) in the Mongoose network library (≤7.20) and characterizes them as heap‑based overflow, stack‑based overflow, and a trivially exploitable authorization bypass.

