CVE-2026-73253Disclosure(cesanta / mongoose)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_cert_san() and mg_tls_verify_cert_cn() functions in src/tls_builtin.c call mg_match(), whose wildcard can cross DNS label boundaries, so a pattern such as *.example.com can match foo.bar.example.com. The resulting hostname verification bypass permits interception and modification of TLS traffic. This issue is fixed in version 7.22.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongoose

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mongoose

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-21: 1Technical Details · 2026-08-21: 108-21
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Improper Certificate Validation #vulnerabilities in #Mongoose. CVE-2026-73251 CVSS: 9.3 / CVE-2026-73253 CVSS: 9.1. These vulnerabilities can lead to TLS traffic interception and modification #MITM! Time to #Patch #Patch #Patch

    Post summary

    The tweet announces two high‑severity certificate validation vulnerabilities in Mongoose, providing CVE IDs, CVSS scores, and describing the potential MITM impact, but offers no PoC, exploit code, or specific patch details.

    01000297
    7.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcesantamongoose---

Explore more