云虫漏洞库

CVE-2026-11404 - Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single crafted ClientHello with an oversized session id length to read past the receive buffer, crashing any HTTPS, MQTTS, or WSS service built on MG_TLS_BUILT - 漏洞详情

漏洞编号:CVE-2026-11404

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-11404

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-125

发布/更新时间:2026-07-09 / 2026-08-29

漏洞描述

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single crafted ClientHello with an oversized session id length to read past the receive buffer, crashing any HTTPS, MQTTS, or WSS service built on MG_TLS_BUILTIN.

相关链接

相关漏洞

« 返回首页