JLSEC-2026-373

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-373.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-373.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-373
Upstream
  • CVE-2026-6986
  • EUVD-2026-25662
Published
2026-04-30T19:30:31.295Z
Modified
2026-04-30T19:45:05.918809Z
Severity
  • 2.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
[none]
Details

A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mgaesgcmdecrypt of the file /src/tlsaes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic signature. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 7.21 is capable of addressing this issue. It is advisable to upgrade the affected component. VulDB has contacted the vendor early and they confirmed quickly, that this issue got fixed already.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "published": "2026-04-25T17:16:33.700Z",
            "modified": "2026-04-29T19:00:39.740Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-6986",
            "imported": "2026-04-30T18:54:48.251Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6986",
            "database_specific": {
                "status": "Analyzed"
            },
            "id": "CVE-2026-6986"
        },
        {
            "published": "2026-04-25T16:30:13Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-25662",
            "imported": "2026-04-30T18:54:52.194Z",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25662",
            "id": "EUVD-2026-25662",
            "modified": "2026-04-27T13:36:06Z"
        }
    ]
}
References

Affected packages

Julia / Mongoose_jll

Package

Name
Mongoose_jll
Purl
pkg:julia/Mongoose_jll?uuid=0a8a3f5b-4c0e-5906-8e29-5b3fee15539c

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.21.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-373.json"