Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification
Published Apr 25, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.25%
Description
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic signature. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 7.21 is capable of addressing this issue. It is advisable to upgrade the affected component. VulDB has contacted the vendor early and they confirmed quickly, that this issue got fixed already.
Affected products
-
Affected
- 7.0
- 7.1
- 7.10
- 7.11
- 7.12
- 7.13
- 7.14
- 7.15
- 7.16
- 7.17
- 7.18
- 7.19
- 7.2
- 7.20
- 7.3
- 7.4
- 7.5
- 7.6
- 7.7
- 7.8
- 7.9
Unaffected
- 7.21
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat rates this vulnerability as Low impact with a CVSS score of 3.7. No Red Hat supported products ship the Cesanta Mongoose library, and the only affected packages are community ones. The vulnerability is specific to Mongoose's built-in TLS implementation, commonly used in embedded and IoT deployments whilst on Linux distributions applications tend to build against OpenSSL or mbedTLS which are not affected. Even where built-in TLS is in use, an attacker would need an active man-in-the-middle position on the network and prior knowledge of the plaintext layout at specific byte offsets to tamper with data in transit. The impact is limited to integrity within a single TLS session, with no effect on confidentiality or availability.
Red Hat mitigation
If you are compiling Mongoose from source, build it against OpenSSL or mbedTLS instead of the built-in TLS stack by setting MG_TLS=MG_TLS_OPENSSL or MG_TLS=MG_TLS_MBED. For applications where switching TLS backends is not an option, restricting network access to the Mongoose service reduces the risk of a man-in-the-middle attack reaching the vulnerable code path.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-6986 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2461830 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25662 Advisory
- https://github.com/cesanta/mongoose/releases/tag/7.21 patchRelease Notes
- https://github.com/dwBruijn/CVEs/blob/main/Mongoose/AESGCM.md exploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6986
- https://vuldb.com/submit/796231 third-party-advisoryThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359529 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359529/cti signaturepermissions-requiredPermissions RequiredVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2026-6986
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6986 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2461830 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25662 | Advisory | |
| https://github.com/cesanta/mongoose/releases/tag/7.21 | patchRelease Notes | |
| https://github.com/dwBruijn/CVEs/blob/main/Mongoose/AESGCM.md | exploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6986 | ||
| https://vuldb.com/submit/796231 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/359529 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/359529/cti | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://www.cve.org/CVERecord?id=CVE-2026-6986 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data