CVE-2026-73257
Last modified
CVE-2026-73257 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and prioritize chunked encoding, while a Content-Length-preferring reverse proxy can use a different request boundary. This CL.TE desynchronization can inject requests that access or modify resources in another user context. This issue is fixed in version 7.22.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| cesanta | mongoose | < 7.22 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-73257?
How severe is CVE-2026-73257?
How do I fix CVE-2026-73257?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73250Notepad++ is a free and open-source source code editor. Prio…5.4
- CVE-2026-73251Mongoose is an embedded web server and network library. Prio…9.3
- CVE-2026-73253Mongoose is an embedded web server and network library. Prio…9.1
- CVE-2026-73254Mongoose is an embedded web server and network library. Prio…5.4
- CVE-2026-73255Mongoose is an embedded web server and network library. Prio…6.5
- CVE-2026-73256Mongoose is an embedded web server and network library. Prio…9.1
- CVE-2026-73258Mongoose is an embedded web server and network library. Prio…6.5
- CVE-2026-73259Mongoose is an embedded web server and network library. Prio…5.4
- CVE-2026-7326A cross-site request forgery vulnerability in the Admin UI o…8.8
- CVE-2026-73262Prowler is a cloud security platform. Prior to 5.37.0, Prowl…5.4
- CVE-2026-73263Prowler is a cloud security platform. Prior to 5.36.0, the K…9.9
- CVE-2026-73264Prowler is a cloud security platform. Prior to 5.33.1, an au…7.6
Are you affected by CVE-2026-73257?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
