
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2966 is a DNS Transaction ID predictability vulnerability in Cesanta Mongoose up to and including version 7.20, affecting the mg_sendnsreq() function in /src/dns.c. The flaw causes DNS transaction IDs to always resolve to the constant value of 1 for non-overlapping queries, enabling trivial DNS spoofing attacks. It was disclosed on February 23, 2026, with a public proof-of-concept released simultaneously. The CVSS v3.1 base score is 3.7 (Low), though the practical impact is significantly higher due to 100% spoofing reliability (Red Hat Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-330 (Use of Insufficiently Random Values) and CWE-334 (Small Space of Random Values). In dns.c at line 258, the transaction ID is generated as d->txnid = reqs ? (uint16_t)(reqs->txnid + 1) : 1; — intending sequential IDs, but because each resolved query is immediately freed from active_dns_requests before the next query is created, reqs is always NULL, making the txnid a constant value of 1. The response handler (dns_cb) performs no validation beyond matching the 16-bit txnid — no source IP verification, no query name cross-check, and no DNSSEC — meaning any attacker who can send a spoofed UDP packet with txnid=1 before the legitimate DNS response arrives will succeed with 100% reliability. When using Mongoose's built-in TCP/IP stack (MIP), the attack surface is further amplified by sequential ephemeral source ports and deterministic TCP Initial Sequence Numbers, reducing the entire connection establishment path to zero effective entropy (PoC Write-up).
Successful exploitation enables DNS cache poisoning with 100% reliability, allowing an attacker to redirect any hostname resolution performed by a Mongoose-based application to an attacker-controlled server. Concrete consequences include man-in-the-middle interception of HTTP API calls, MQTT broker connections, NTP, and OTA update traffic; credential theft of authentication tokens, API keys, or device certificates; and delivery of malicious firmware via OTA update redirection (Mongoose's OTA mechanism uses only CRC32 verification, not cryptographic signatures). The vulnerability has no confidentiality impact per CVSS scoring, but the integrity impact is significant as it allows full control over hostname resolution for any affected embedded device or application (PoC Write-up, Red Hat Bugzilla).
A public proof-of-concept exploit is available on GitHub, consisting of a victim C program (dns_victim.c) and an attacker Python script (dns_spoof.py) that demonstrates 100% DNS spoofing success against Mongoose 7.20. The attack requires no authentication and no prior traffic observation — only the ability to send a spoofed UDP packet to the victim's DNS client port before the legitimate response arrives. The EPSS score is 0.031% (low automated exploitation probability), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the disclosure date. The vendor (Cesanta) did not respond to the researcher's disclosure (PoC Write-up, Red Hat Advisory).
MG_EPHEMERAL_PORT_BASE, making them predictable).txnid=1, the attacker-controlled IP address in the answer section, and the correct question section matching the victim's query (using a tool like the provided dns_spoof.py).0x0001 (txnid=1) in outgoing UDP DNS requests; unexpected DNS responses arriving from non-configured DNS server IP addresses; outbound connections to unexpected IP addresses following DNS resolution events.MG_EPHEMERAL_PORT_BASE, enabling easy prediction and targeting.Upgrade Cesanta Mongoose to a version newer than 7.20, which addresses the constant transaction ID generation in mg_sendnsreq(). As a workaround where upgrading is not immediately possible, configure Mongoose applications to use hardcoded IP addresses instead of hostnames for critical connections (API servers, MQTT brokers, OTA update endpoints), eliminating reliance on DNS resolution. Additionally, deploy network-level controls such as DNS-over-TLS or DNSSEC where supported, and restrict UDP traffic to trusted DNS servers only. Organizations using Mongoose's built-in MIP stack should also be aware of the compounding sequential source port and deterministic TCP ISN issues, which require separate remediation (Red Hat Advisory, Red Hat Bugzilla).
Red Hat tracked the vulnerability via Bugzilla (Bug 2441855) and published a security advisory, classifying it as medium severity. The researcher (dwBruijn) noted that the vendor (Cesanta) did not respond to the disclosure, resulting in a public release without a coordinated patch. The vulnerability drew comparisons to similar DNS transaction ID weaknesses CVE-2024-52616 and CVE-2022-30295, highlighting a recurring class of issue in embedded networking libraries (Red Hat Bugzilla, PoC Write-up).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."