CVE-2026-73258CWE-697

CVE-2026-73258

Medium · published August 20, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
18.7
In the wild
Unconfirmed
What it is

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s[b + 1], and s[h2] and s[h2 + 1], use an incorrect AND condition and stop when either character resembles part of a CRLF terminator. This truncates headers, filenames, or boundaries and can cause an application to accept dangerous content after seeing a misleading Content-Type value. This issue is fixed in version 7.22.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00267 · 18.7th percentile
Weakness
CWE-697 · Incorrect Comparison
Published
2026-08-20T22:16Z
References (5)
EPSS history
Timeline
  • 20 AUG 17:36Z
    Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart
    cvelistv5