Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-73259 — Mongoose: Reflected XSS via decoded URI in directory listing render

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to…

mongoose | Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-73258 — Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/…

mongoose | Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.1 CRITICAL
CVE-2026-73257 — Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked…

mongoose | Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.1 CRITICAL
CVE-2026-73256 — Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: …

mongoose | Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-73255 — Mongoose: Path traversal in SSI #include directives enables arbitrary file read

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual …

mongoose | Remote | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.4 MEDIUM
CVE-2026-73254 — Mongoose: Stored XSS via unescaped filenames in directory listing

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a…

mongoose | Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.1 CRITICAL
CVE-2026-73253 — Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a clien…

mongoose | Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.3 CRITICAL
CVE-2026-73251 — Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verific…

Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_b…

mongoose | Remote | Authentication
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
4.6 MEDIUM
CVE-2026-72847 — broot Terminal Escape Sequence Injection via Unsanitized File and Directory Names in the …

broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() call in src/tree_build/builder.rs and i…

| Information Disclosure
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.3 MEDIUM
CVE-2026-72844 — Lean 4 Kernel Type Checking Bypass via Mismatched Structure Projections

The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive in src/kernel/inductive.cpp did not…

| Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-63495 — Libevent: Unbounded memory accumulation in WebSocket server via fragmented frames

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a t…

Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.4 HIGH
CVE-2026-63388 — Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via …

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-sup…

| Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.0 HIGH
CVE-2026-63387 — Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server re…

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the…

Remote | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.2 CRITICAL
CVE-2026-63385 — Libevent: HTTP header handling bugs create risk of access control bypass.

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into liter…

Remote | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.7 HIGH
CVE-2026-63384 — Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` r…

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode…

Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.7 HIGH
CVE-2026-63383 — Libevent: decode_tag_internal() can lead to out-of-bounds read

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five byt…

Remote | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.2 CRITICAL
CVE-2026-63382 — libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-E…

Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.8 MEDIUM
CVE-2026-63381 — Libevent: Dangling Pointer in `evbuffer_add_buffer_reference`

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len…

| Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.7 MEDIUM
CVE-2026-63380 — Libevent: Null Pointer Dereference in `evws_new_session`

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but…

| Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.3 MEDIUM
CVE-2026-63379 — Libevent: HTTP Header smuggling

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fi…

Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
Showing 20 of 12785 Results