{"id":"CVE-2019-12951","details":"An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.","modified":"2026-08-07T14:49:05.949414Z","published":"2019-06-24T23:15:12.210Z","references":[{"type":"ADVISORY","url":"https://github.com/cesanta/mongoose/releases/tag/6.15"},{"type":"FIX","url":"https://github.com/cesanta/mongoose/commit/b3e0f780c34cea88f057a62213c012aa88fe2deb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cesanta/mongoose","events":[{"introduced":"0"},{"fixed":"d5beb7ba3f3767891f3d85945d7d33c1d8596e37"},{"fixed":"b3e0f780c34cea88f057a62213c012aa88fe2deb"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.15"}]}}],"versions":["6.14","6.13","6.12","6.11","6.10","6.9","6.7","6.6","6.5","6.4","6.3","6.2","6.1","6.0","5.6","5.5_20140120","5.5","5.4","5.3","5.2","5.1","5.0","4.1","4.0","3.8","3.7","3.6","3.5","3.4","3.3","3.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12951.json","vanir_signatures_modified":"2026-08-07T14:49:05Z","vanir_signatures":[{"id":"CVE-2019-12951-02b35968","signature_type":"Function","signature_version":"v1","source":"https://github.com/cesanta/mongoose/commit/b3e0f780c34cea88f057a62213c012aa88fe2deb","target":{"file":"src/mg_mqtt.c","function":"parse_mqtt"},"deprecated":false,"digest":{"function_hash":"198169568359688866823416702201207463449","length":3484}},{"digest":{"line_hashes":["318451959179559600212943761384714751553","203506875419145949752113475847773794541","300124475507211204145507290533671466820","99989783270940607929970042812623215153","113964899949487998914705191903055108661","220909073243904259200325940333054122391","181963326070752889268247635560144729332","194616825067426885033132069526593454473","32297059813226418094209480233904743941","158743914063726245224935765878676000180","242058701329965836886413194556142218028","202685874918949681063835384083901977148","298896519032976953735511227272721233568","234203154594107864103826915773165607850","156914595055367849120805501920246572284","316546846396089965587538649279488520373","115818615017429595644330698564950237276","212090324586127216818259759998632085017","280321884277974389504920536560302828502"],"threshold":0.9},"id":"CVE-2019-12951-a154c9ac","signature_type":"Line","signature_version":"v1","source":"https://github.com/cesanta/mongoose/commit/b3e0f780c34cea88f057a62213c012aa88fe2deb","target":{"file":"mongoose.c"},"deprecated":false},{"deprecated":false,"digest":{"length":3484,"function_hash":"198169568359688866823416702201207463449"},"id":"CVE-2019-12951-b0b505de","signature_type":"Function","signature_version":"v1","source":"https://github.com/cesanta/mongoose/commit/b3e0f780c34cea88f057a62213c012aa88fe2deb","target":{"file":"mongoose.c","function":"parse_mqtt"}},{"id":"CVE-2019-12951-b1da9acb","signature_type":"Line","signature_version":"v1","source":"https://github.com/cesanta/mongoose/commit/b3e0f780c34cea88f057a62213c012aa88fe2deb","target":{"file":"src/mg_mqtt.c"},"deprecated":false,"digest":{"line_hashes":["318451959179559600212943761384714751553","203506875419145949752113475847773794541","300124475507211204145507290533671466820","99989783270940607929970042812623215153","113964899949487998914705191903055108661","220909073243904259200325940333054122391","181963326070752889268247635560144729332","194616825067426885033132069526593454473","32297059813226418094209480233904743941","158743914063726245224935765878676000180","242058701329965836886413194556142218028","202685874918949681063835384083901977148","298896519032976953735511227272721233568","234203154594107864103826915773165607850","156914595055367849120805501920246572284","316546846396089965587538649279488520373","115818615017429595644330698564950237276","212090324586127216818259759998632085017","280321884277974389504920536560302828502"],"threshold":0.9}}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}