Junglewise Threat Intelligence

CVE-2026-73257: Mongoose HTTP request desynchronization

CVE-2026-73257 · Severity: critical · CVSS 9.1 · Published 2026-08-20

Vendors: Cesanta.

Executive brief

Mongoose is an embedded web server used in many IoT devices and applications. A remote attacker can exploit conflicting handling of Content-Length and Transfer-Encoding headers to inject HTTP requests that bypass authentication and access or modify data belonging to other users. No authentication is required, and the attack can be performed over the network.

Technical details

The vulnerability is a request smuggling/desynchronization (CL.TE) flaw in Mongoose's HTTP parsing logic in src/http.c. The mg_http_parse() and http_cb() functions accept both Content-Length and Transfer-Encoding: chunked headers in the same request, prioritizing chunked encoding. When a reverse proxy in front of Mongoose prefers Content-Length, the two systems interpret the request boundary differently, allowing an attacker to inject hidden requests. This permits unauthorized access to or modification of resources in other users' contexts. The flaw affects all versions prior to 7.22, which includes the fix. The attack requires network reachability to the Mongoose server but no prior authentication.

Affected products

  • Cesanta Mongoose prior to 7.22

Timeline

  • 2026-08-20: disclosed
  • 2026-06-23: patched: Fix merged in version 7.22

References