Description

An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.

INFO

Published Date :

2025-09-29T00:00:00.000Z

Last Modified :

2025-10-01T15:21:21.511Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-51495 vulnerability.

Vendors Products
Cesanta
  • Mongoose

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact