๐Ÿ” CVE Alert

CVE-2026-73259

MEDIUM 5.4

Mongoose: Reflected XSS via decoded URI in directory listing render

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI into the title and h1 elements without HTML entity encoding. The resulting reflected cross-site scripting executes in the Mongoose origin and can expose session data or perform actions as the victim. This issue is fixed in version 7.22.

CWE CWE-79
Vendor cesanta
Product mongoose
Published Aug 20, 2026
Last Updated Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for cesanta mongoose

Be the first to know when new medium vulnerabilities affecting cesanta mongoose are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

cesanta / mongoose
< 7.22

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cesanta/mongoose/security/advisories/GHSA-9cwm-487w-h25w github.com: https://github.com/cesanta/mongoose/pull/3611 github.com: https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71 github.com: https://github.com/cesanta/mongoose/releases/tag/7.22