
Mongoose network library <= 7.20 CVE-2026-5244 - mg_tls_recv_cert pubkey heap-based overflow (exploitable) CVE-2026-5245 - mDNS Record stack-based overflow (exploitable) CVE-2026-5246 - authorization bypass via P-384 Public Key (trivially exploitable) Fun ride. https://t.co/KUBymdWrJF
Post summary
The tweet discloses three CVEs in the Mongoose library, describing the vulnerability types and stating they are exploitable, but offers no PoC, exploitation evidence, or mitigation information.
