CVE-2026-73251
Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tlsbuiltin.c, the mgtlsinit() function stores the bundle in tls->cabundleder while tls->cader.len remains zero, and mgtlsrecvcert() uses tlsbundlefind() to accept a Common Name match without calling mgtlsverifycert_signature(). A forged self-signed certificate can therefore satisfy hostname and CertificateVerify checks and enable interception, credential disclosure, traffic modification, and malicious responses. This issue is fixed in version 7.23.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/cesanta/mongoose/releases/tag/7.23, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73251.json, https://github.com/cesanta/mongoose/security/advisories/GHSA-qj6j-2692-v2r8, https://nvd.nist.gov/vuln/detail/CVE-2026-73251, https://github.com/cesanta/mongoose/commit/2988bc9df3a5efc9539471cb7455975fa25df483