CVE-2026-2966

EUVD-2026-7602
A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently random values. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 31.39%
Affected Products (NVD)
VendorProductVersion
cesantamongoose
𝑥
≤ 7.20
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
mongoose
forky
7.22+ds-1
fixed
sid
7.23+ds-1
fixed
swupdate
bookworm
no-dsa
bullseye
postponed
forky
2026.05.1+dfsg-1
fixed
sid
2026.05.1+dfsg-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
opencpn
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
Common Weakness Enumeration