CVE-2026-6986 | Cesanta Mongoose up to 7.20 GCM Authentication Tag /src/tls_aes128.c mg_aes_gcm_decrypt signature verification
A vulnerability categorized as problematic has been discovered in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic signature.
This vulnerability is listed as CVE-2026-6986. The attack may be performed from remote. In addition, an exploit is available.
It is advisable to upgrade the affected component.
VulDB has contacted the vendor early and they confirmed quickly, that this issue got fixed already.