CVE-2026-2966
A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently random values. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.38%
- CWE
- CWE-330, CWE-310
- Published
- 2026-02-23
- Last modified
- 2026-03-12
Affected products
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
Weakness type
Related vulnerabilities
- CVE-2026-53939 — OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption
- CVE-2026-86187 — WWBN AVideo Weak PRNG Password Generation via External Login
- CVE-2026-17274 — IBM i is Affected By Multiple Vulnerabilities in Debug Server
- CVE-2026-3416 — Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads
- CVE-2026-66047 — ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE
- CVE-2026-81852 — AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
- CVE-2026-82555 — TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
- CVE-2026-19485 — Bucket Squatting in Vertex AI Search for Commerce