JLSEC-2026-370

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-370.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-370.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-370
Upstream
  • CVE-2026-5245
  • EUVD-2026-18183
  • GHSA-2rqj-7x75-2684
Published
2026-04-30T19:30:31.295Z
Modified
2026-04-30T20:02:32.299810733Z
Severity
  • 2.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function...
Details

A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handlemdnsrecord of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the argument buf results in stack-based buffer overflow. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is said to be difficult. The exploit has been made public and could be used. Upgrading to version 7.21 will fix this issue. The patch is named 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Database specific
{
    "sources": [
        {
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-5245",
            "database_specific": {
                "status": "Analyzed"
            },
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5245",
            "modified": "2026-04-29T21:44:23.490Z",
            "id": "CVE-2026-5245",
            "imported": "2026-04-30T18:54:47.964Z",
            "published": "2026-04-02T10:16:17.443Z"
        },
        {
            "url": "https://api.github.com/advisories/GHSA-2rqj-7x75-2684",
            "html_url": "https://github.com/advisories/GHSA-2rqj-7x75-2684",
            "modified": "2026-04-02T12:31:13Z",
            "id": "GHSA-2rqj-7x75-2684",
            "imported": "2026-04-30T18:55:54.242Z",
            "published": "2026-04-02T12:31:05Z"
        },
        {
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-18183",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18183",
            "modified": "2026-04-02T14:27:27Z",
            "id": "EUVD-2026-18183",
            "imported": "2026-04-30T18:54:56.696Z",
            "published": "2026-04-02T09:00:19Z"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / Mongoose_jll

Package

Name
Mongoose_jll
Purl
pkg:julia/Mongoose_jll?uuid=0a8a3f5b-4c0e-5906-8e29-5b3fee15539c

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.21.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-370.json"