CVE-2024-42392EPSS p13.0%

CVE-2024-42392CVE-2024-42392

cesanta / mongoose

Description

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

Scoring

CVSS 4.0 ()
VectorCVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H
EPSS0.23% probability of exploitation · percentile 13.0% · 2026-10-05T12:00:23Z
Last modified2026-09-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.