THREAT OPS › Threat News › [NVD] CVE-2026-11404 (HIGH 7.5) — Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A
[NVD] CVE-2026-11404 (HIGH 7.5) — Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A
CVE-2026-11404 CVSS: 7.5 HIGH Published: 2026-07-09T16:16:34.640
Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single cra
Indicators of compromise
- CVE-2026-11404cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-11404