CVE-2026-73251Patch(cesanta / mongoose)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cesanta mongoose systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function stores the bundle in tls->ca_bundle_der while tls->ca_der.len remains zero, and mg_tls_recv_cert() uses tls_bundle_find() to accept a Common Name match without calling mg_tls_verify_cert_signature(). A forged self-signed certificate can therefore satisfy hostname and CertificateVerify checks and enable interception, credential disclosure, traffic modification, and malicious responses. This issue is fixed in version 7.23.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongoose

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mongoose

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-21: 1Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 108-21
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • CCB Alert@CCBalert
    Patch

    Warning: Critical Improper Certificate Validation #vulnerabilities in #Mongoose. CVE-2026-73251 CVSS: 9.3 / CVE-2026-73253 CVSS: 9.1. These vulnerabilities can lead to TLS traffic interception and modification #MITM! Time to #Patch #Patch #Patch

    Post summary

    A warning about two high‑CVSS improper certificate validation CVEs in Mongoose, emphasizing that they can enable MITM attacks and urging immediate patching.

    01000297
    7.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcesantamongoose---

Explore more