{"apiVersion":"1.0","identifier":"CVE-2026-73259","description":"Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI into the title and h1 elements without HTML entity encoding. The resulting reflected cross-site scripting executes in the Mongoose origin and can expose session data or perform actions as the victim. This issue is fixed in version 7.22.","publishedAt":"2026-08-20T18:16:47","lastModifiedAt":"2026-08-20T20:17:46","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73259","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","epssProbability":0.0023,"riskScore":0.55,"affectedProduct":"mongoose","affectedVersions":"<7.22","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-73259","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-73259","en":"https://www.redsauce.net/en/cves/CVE-2026-73259","fr":"https://www.redsauce.net/fr/cves/CVE-2026-73259","pt":"https://www.redsauce.net/pt/cves/CVE-2026-73259","de":"https://www.redsauce.net/de/cves/CVE-2026-73259","sk":"https://www.redsauce.net/sk/cves/CVE-2026-73259","el":"https://www.redsauce.net/el/cves/CVE-2026-73259"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-73259"}}