Out-of-bounds read in Mongoose - CVE-2026-52053
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or disclose sensitive information.
The vulnerability exists due to out-of-bounds read in the rx_ip6() function when parsing crafted IPv6 extension headers. A remote attacker can send a specially crafted IPv6 packet to cause a denial of service or disclose sensitive information.
Exploitation requires access to the same local network segment and affects deployments using the built-in TCP/IP stack with MG_ENABLE_TCPIP enabled.