CVE-2026-2966: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-2966 is a DNS Transaction ID predictability vulnerability in Cesanta Mongoose up to and including version 7.20, affecting the mg_sendnsreq() function in /src/dns.c. The flaw causes DNS transaction IDs to always resolve to the constant value of 1 for non-overlapping queries, enabling trivial DNS spoofing attacks. It was disclosed on February 23, 2026, with a public proof-of-concept released simultaneously. The CVSS v3.1 base score is 3.7 (Low), though the practical impact is significantly higher due to 100% spoofing reliability (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-330 (Use of Insufficiently Random Values) and CWE-334 (Small Space of Random Values). In dns.c at line 258, the transaction ID is generated as d->txnid = reqs ? (uint16_t)(reqs->txnid + 1) : 1; — intending sequential IDs, but because each resolved query is immediately freed from active_dns_requests before the next query is created, reqs is always NULL, making the txnid a constant value of 1. The response handler (dns_cb) performs no validation beyond matching the 16-bit txnid — no source IP verification, no query name cross-check, and no DNSSEC — meaning any attacker who can send a spoofed UDP packet with txnid=1 before the legitimate DNS response arrives will succeed with 100% reliability. When using Mongoose's built-in TCP/IP stack (MIP), the attack surface is further amplified by sequential ephemeral source ports and deterministic TCP Initial Sequence Numbers, reducing the entire connection establishment path to zero effective entropy (PoC Write-up).

Impact

Successful exploitation enables DNS cache poisoning with 100% reliability, allowing an attacker to redirect any hostname resolution performed by a Mongoose-based application to an attacker-controlled server. Concrete consequences include man-in-the-middle interception of HTTP API calls, MQTT broker connections, NTP, and OTA update traffic; credential theft of authentication tokens, API keys, or device certificates; and delivery of malicious firmware via OTA update redirection (Mongoose's OTA mechanism uses only CRC32 verification, not cryptographic signatures). The vulnerability has no confidentiality impact per CVSS scoring, but the integrity impact is significant as it allows full control over hostname resolution for any affected embedded device or application (PoC Write-up, Red Hat Bugzilla).

Exploitability

A public proof-of-concept exploit is available on GitHub, consisting of a victim C program (dns_victim.c) and an attacker Python script (dns_spoof.py) that demonstrates 100% DNS spoofing success against Mongoose 7.20. The attack requires no authentication and no prior traffic observation — only the ability to send a spoofed UDP packet to the victim's DNS client port before the legitimate response arrives. The EPSS score is 0.031% (low automated exploitation probability), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the disclosure date. The vendor (Cesanta) did not respond to the researcher's disclosure (PoC Write-up, Red Hat Advisory).

Exploitation steps

  1. Reconnaissance: Identify target systems running Cesanta Mongoose version 7.20 or earlier that perform DNS resolution (e.g., embedded IoT devices, web servers using Mongoose's networking library).
  2. Position for race condition: Gain a network position capable of sending UDP packets to the victim's DNS client port (UDP source port, typically ephemeral; when using Mongoose's built-in MIP stack, source ports are sequential starting from MG_EPHEMERAL_PORT_BASE, making them predictable).
  3. Monitor for DNS queries: Optionally sniff network traffic to detect outgoing DNS queries from the victim, or simply send spoofed responses preemptively since the txnid is always 1.
  4. Craft spoofed DNS response: Build a UDP DNS response packet with txnid=1, the attacker-controlled IP address in the answer section, and the correct question section matching the victim's query (using a tool like the provided dns_spoof.py).
  5. Race the legitimate DNS server: Send the spoofed response to the victim's DNS client port before the legitimate DNS server responds. Because txnid=1 is always correct and no source IP validation is performed, the victim's Mongoose resolver accepts the spoofed response.
  6. Achieve redirection: The victim application connects to the attacker's IP instead of the legitimate server, enabling MitM interception, credential harvesting, or malicious firmware delivery (PoC Write-up).

Indicators of compromise

  • Network: DNS query traffic from Mongoose-based devices always using transaction ID 0x0001 (txnid=1) in outgoing UDP DNS requests; unexpected DNS responses arriving from non-configured DNS server IP addresses; outbound connections to unexpected IP addresses following DNS resolution events.
  • Network: When using Mongoose's built-in MIP stack, DNS queries originating from sequential ephemeral source ports starting at MG_EPHEMERAL_PORT_BASE, enabling easy prediction and targeting.
  • Logs: Application logs showing connections to unexpected remote IP addresses for known hostnames (e.g., cloud API endpoints, MQTT brokers resolving to unknown IPs).
  • File System: Unexpected firmware images or configuration files downloaded via OTA update mechanisms from unrecognized servers.
  • Process/Behavior: Mongoose-based applications establishing TLS or plaintext connections to IP addresses not matching expected infrastructure, particularly for update servers, API endpoints, or broker connections (PoC Write-up).

Mitigation and workarounds

Upgrade Cesanta Mongoose to a version newer than 7.20, which addresses the constant transaction ID generation in mg_sendnsreq(). As a workaround where upgrading is not immediately possible, configure Mongoose applications to use hardcoded IP addresses instead of hostnames for critical connections (API servers, MQTT brokers, OTA update endpoints), eliminating reliance on DNS resolution. Additionally, deploy network-level controls such as DNS-over-TLS or DNSSEC where supported, and restrict UDP traffic to trusted DNS servers only. Organizations using Mongoose's built-in MIP stack should also be aware of the compounding sequential source port and deterministic TCP ISN issues, which require separate remediation (Red Hat Advisory, Red Hat Bugzilla).

Community reactions

Red Hat tracked the vulnerability via Bugzilla (Bug 2441855) and published a security advisory, classifying it as medium severity. The researcher (dwBruijn) noted that the vendor (Cesanta) did not respond to the disclosure, resulting in a public release without a coordinated patch. The vulnerability drew comparisons to similar DNS transaction ID weaknesses CVE-2024-52616 and CVE-2022-30295, highlighting a recurring class of issue in embedded networking libraries (Red Hat Bugzilla, PoC Write-up).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

swupdate

Affected

sid

swupdate: 2025.12+dfsg-10

Fixed

trixie

swupdate

Affected

Ubuntu

Unknown

devel

opencpn

Unknown

focal (esm-apps)

opencpn

Unknown

jammy

opencpn

Unknown

jammy (esm-apps)

opencpn

Unknown

noble

opencpn

Unknown

noble (esm-apps)

opencpn

Unknown

resolute

opencpn

Unknown

resolute (esm-apps)

opencpn

Unknown

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management