JLSEC-2026-369

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-369.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-369.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-369
Upstream
  • CVE-2026-5244
  • EUVD-2026-18170
  • GHSA-7vfw-f3r2-9m2j
Published
2026-04-30T19:30:31.295Z
Modified
2026-04-30T20:02:32.722624616Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function...
Details

A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mgtlsrecv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.21 mitigates this issue. The name of the patch is 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Database specific
{
    "sources": [
        {
            "imported": "2026-04-30T18:54:47.868Z",
            "id": "CVE-2026-5244",
            "modified": "2026-04-29T21:46:14.623Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-5244",
            "database_specific": {
                "status": "Analyzed"
            },
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5244",
            "published": "2026-04-02T08:16:28.683Z"
        },
        {
            "html_url": "https://github.com/advisories/GHSA-7vfw-f3r2-9m2j",
            "id": "GHSA-7vfw-f3r2-9m2j",
            "imported": "2026-04-30T18:55:48.143Z",
            "modified": "2026-04-02T09:30:31Z",
            "url": "https://api.github.com/advisories/GHSA-7vfw-f3r2-9m2j",
            "published": "2026-04-02T09:30:25Z"
        },
        {
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18170",
            "id": "EUVD-2026-18170",
            "imported": "2026-04-30T18:54:58.913Z",
            "modified": "2026-04-02T13:31:54Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-18170",
            "published": "2026-04-02T08:00:19Z"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / Mongoose_jll

Package

Name
Mongoose_jll
Purl
pkg:julia/Mongoose_jll?uuid=0a8a3f5b-4c0e-5906-8e29-5b3fee15539c

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.21.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-369.json"