Home

Description

An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.

PUBLISHED Reserved 2025-06-16 | Published 2025-09-29 | Updated 2025-10-01 | Assigner mitre

References

github.com/cesanta/mongoose

github.com/cesanta/mongoose/pull/3131

github.com/cainiao159357/CVE-2025-51495

cve.org (CVE-2025-51495)

nvd.nist.gov (CVE-2025-51495)

Download JSON