SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-73259

MEDIUM · CVSS 5.4 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Mongoose versions prior to 7.22 are vulnerable to reflected cross-site scripting due to improper handling of percent-encoded request paths, which allows remote attackers to inject malicious scripts into web pages served by the embedded web server. This vulnerability can lead to session data exposure or unauthorized actions on behalf of users who visit the crafted URL. Organizations using Mongoose in their applications should prioritize upgrading to version 7.22 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73259
Severity
MEDIUM
CVSS
5.4
EPSS
0.28%

Original NVD Description

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI into the title and h1 elements without HTML entity encoding. The resulting reflected cross-site scripting executes in the Mongoose origin and can expose session data or perform actions as the victim. This issue is fixed in version 7.22.