CVE-2026-5244 | Cesanta Mongoose up to 7.20 TLS 1.3 mongoose.c mg_tls_recv_cert pubkey heap-based overflow
A vulnerability categorized as critical has been discovered in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-5244. The attack may be launched remotely. Furthermore, there is an exploit available.
It is advisable to upgrade the affected component.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.