Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.3
Cesanta Mongoose allows attackers to bypass encryption, read sensitive data
CVE-2026-2968
Summary
A bug in Cesanta Mongoose's encryption system allows attackers to bypass the encryption and read sensitive data. This is a serious issue, as it could allow unauthorized access to confidential information. To protect your data, update to the latest version of Cesanta Mongoose.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| cesanta | mongoose | <= 7.20 | – |
Original title
A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Hand...
Original description
A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of cryptographic signature. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0
2.6
nvd CVSS3.1
3.7
nvd CVSS4.0
6.3
Vulnerability type
CWE-345
CWE-347
Improper Verification of Cryptographic Signature
- https://github.com/dwBruijn/CVEs/blob/main/Mongoose/ChaCha20Poly1305.md Exploit Third Party Advisory
- https://github.com/dwBruijn/CVEs/blob/main/Mongoose/ChaCha20Poly1305.md#poc Exploit Third Party Advisory
- https://vuldb.com/?ctiid.347335 Permissions Required VDB Entry
- https://vuldb.com/?id.347335 Third Party Advisory VDB Entry
- https://vuldb.com/?submit.757091 Third Party Advisory VDB Entry
Published: 23 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026