Loading
The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests.
Cite this page
CVE-2023-34188. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2023-34188
Use CWE-1284, Cesanta vendor hub and Mongoose product page to widen CVE-2023-34188 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-51495, CVE-2026-6985 and CVE-2026-5244 for nearby disclosures in the same product family.