
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2967 is a blind TCP RST injection vulnerability in Cesanta Mongoose's built-in TCP/IP stack (MIP), affecting versions up to and including 7.20. The flaw resides in the getpeer() function within /src/net_builtin.c, which matches incoming TCP segments to existing connections using only the port pair while ignoring the source IP address, and in rx_tcp(), which terminates connections upon receiving a RST flag without validating the sequence number against the receive window. This allows any network-adjacent attacker to terminate arbitrary TCP sessions with a single forged RST packet. It was publicly disclosed on February 23, 2026, with a CVSS v3.1 base score of 3.7 (Low) (Red Hat Advisory, Red Hat Bugzilla).
The vulnerability has two distinct root causes classified under CWE-940 (Improper Verification of Source of a Communication Channel) and CWE-1285 (Improper Validation of Specified Index, Position, or Offset in Input). First, getpeer() (net_builtin.c:552–555) matches TCP connections solely on the port pair (c->loc.port == pkt->tcp->dport and c->rem.port == pkt->tcp->sport) without ever comparing c->rem.addr against the packet's source IP, enabling any host knowing the port pair to inject packets into an existing connection. Second, rx_tcp() (net_builtin.c:1537–1539) unconditionally calls mg_error(c, "peer RST") upon seeing the RST flag — the code even contains a TODO comment acknowledging the missing window validation — violating RFC 5961 Section 3.2, which requires RCV.NXT <= SEG.SEQ < RCV.NXT + RCV.WND. An additional amplifying factor is that Mongoose's MIP stack uses deterministic TCP Initial Sequence Numbers derived from the ephemeral port number, making future session hijacking feasible after a successful RST injection (PoC Write-up).
Successful exploitation results in a denial-of-service condition: an attacker can continuously terminate any TCP connection to a Mongoose MIP device — including HTTP, MQTT, and WebSocket sessions — preventing legitimate clients from maintaining sessions. There is no confidentiality or integrity impact under the primary attack scenario; however, the deterministic TCP ISN generation (ISN derived from the ephemeral port number) means a follow-on attacker could predict sequence numbers for subsequent connections, potentially enabling TCP session hijacking beyond mere termination. The impact is scoped to the vulnerable Mongoose instance and does not directly facilitate lateral movement, but persistent DoS against embedded or IoT devices using Mongoose could disrupt critical operational functions (PoC Write-up, Red Hat Bugzilla).
A public proof-of-concept exploit is available on GitHub, authored by researcher dwBruijn, demonstrating successful blind TCP RST injection without requiring root privileges or TAP interfaces (PoC Write-up). The CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. As of the time of reporting, there is no evidence of in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.00145 (0.145%), reflecting low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Attack complexity is rated High, as the attacker must be network-adjacent and know or guess the target port pair (Red Hat Advisory).
MG_ENABLE_TCPIP=1). Determine the listening port (e.g., port 8080 for HTTP) through network scanning.https://github.com/dwBruijn/CVEs/blob/main/Mongoose/tcp_rst.md, place tcp_rst.c in the Mongoose source tree's poc/ directory, and compile: gcc -o tcp_rst tcp_rst.c ../mongoose.c -I.. -DMG_ENABLE_TCPIP=1 -lpthread.getpeer() matches only on ports, the connection is found; because rx_tcp() performs no sequence number or source IP validation, mg_error() is called and the connection is immediately terminated.MG_EV_ERROR events with the message "peer RST" in Mongoose application logs, especially when no legitimate client disconnection is expected; sudden connection termination events without corresponding client-side FIN or application-level close.The primary remediation is to upgrade Cesanta Mongoose to a version newer than 7.20, which should include fixes for source IP validation in getpeer() and sequence number window validation in rx_tcp(). Note that the vendor did not respond to the researcher's disclosure, so patch availability should be verified directly against the Cesanta Mongoose GitHub repository. As a workaround, network-level controls such as ingress filtering (BCP38) and restricting access to Mongoose MIP devices to trusted network segments can reduce the attack surface. Organizations should also consider disabling the MIP built-in TCP/IP stack if an OS-native TCP/IP stack is available, as the vulnerability is specific to the MIP stack (Red Hat Bugzilla, Red Hat Advisory).
The vulnerability was announced via the @CVEnew account on X (Twitter) shortly after publication (X/CVEnew). Red Hat tracked the issue via Bugzilla and assigned it medium priority/severity, indicating it affects packages in their ecosystem (Red Hat Bugzilla). Spain's INCIBE-CERT also published an early warning advisory. The vendor (Cesanta) did not respond to the researcher's disclosure, which was noted in the public write-up and CVE description. No significant broader media coverage or notable researcher commentary beyond the original disclosure has been identified.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."