{"id":"CVE-2023-2905","summary":"Cesanta Mongoose MQTT Message Parsing Heap Overflow","details":"Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be vulnerable. This issue is resolved in version 7.11.\n","modified":"2026-08-12T14:50:40.555728Z","published":"2023-08-09T04:46:14.972Z","database_specific":{"cna_assigner":"AHA","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2905.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2905.json"},{"type":"ADVISORY","url":"https://github.com/cesanta/mongoose/releases/tag/7.11"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-2905"},{"type":"FIX","url":"https://github.com/cesanta/mongoose/pull/2274"},{"type":"EVIDENCE","url":"https://takeonme.org/cves/CVE-2023-2905.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cesanta/mongoose","events":[{"introduced":"b379816178abdcd59135aa32f990a4b3bbbfb54b"},{"fixed":"5c8e05a4fc34c5309ceea887a7e60b895b2100d7"}],"database_specific":{"cpe":"cpe:2.3:a:cesanta:mongoose:7.10:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.10"},{"last_affected":"7.10"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["7.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-2905.json","vanir_signatures_modified":"2026-08-12T14:50:40Z","vanir_signatures":[{"digest":{"length":2019,"function_hash":"322578170098778285952942806764184170488"},"id":"CVE-2023-2905-4da521ed","signature_type":"Function","signature_version":"v1","source":"https://github.com/cesanta/mongoose/commit/5c8e05a4fc34c5309ceea887a7e60b895b2100d7","target":{"file":"mongoose.c","function":"mqtt_cb"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/cesanta/mongoose/commit/5c8e05a4fc34c5309ceea887a7e60b895b2100d7","target":{"file":"mongoose.c"},"deprecated":false,"digest":{"line_hashes":["117949057774234710139995544902745237138","313220653113354972269039999932499615694","248097422983505795697698419060461918","261418787229042588120440473792472697846","264179395874945463223054796764526256741"],"threshold":0.9},"id":"CVE-2023-2905-72b6c1ca","signature_type":"Line"}]}}],"schema_version":"1.9.0"}