CVE-2024-42392

Medium4.0Published on November 18, 2024

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

CVSS score4.0 / 10CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H
Weakness type (CWE)CWE-140
Vendorscesanta

Affected products

VendorsProductVersions
cesantamongoose<= 7.14

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database