CVE-2026-73253
CVE-2026-73253 is a critical-severity vulnerability in Cesanta Mongoose with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-295.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- CVSS v4: 9.1
- EPSS exploit prediction: 0% (26th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-295
- Affected product: Cesanta Mongoose
- Published:
- Last modified:
Description
Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_cert_san() and mg_tls_verify_cert_cn() functions in src/tls_builtin.c call mg_match(), whose wildcard can cross DNS label boundaries, so a pattern such as *.example.com can match foo.bar.example.com. The resulting hostname verification bypass permits interception and modification of TLS traffic. This issue is fixed in version 7.22.
Frequently asked questions
- What is CVE-2026-73253?
- Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_cert_san() and mg_tls_verify_cert_cn() functions in src/tls_builtin.c call mg_match(), whose wildcard can cross DNS label boundaries, so a pattern such as *.example.com can match foo.bar.example.com. The resulting hostname verification bypass permits interception and modification of TLS traffic. This issue is fixed in version 7.22.
- How severe is CVE-2026-73253?
- CVE-2026-73253 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-73253 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (26th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-73253?
- CVE-2026-73253 affects Cesanta Mongoose. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-73253?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-73253 published?
- CVE-2026-73253 was published on 2026-08-20 and last updated on 2026-09-29.
References
- https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71
- https://github.com/cesanta/mongoose/pull/3611
- https://github.com/cesanta/mongoose/releases/tag/7.22
- https://github.com/cesanta/mongoose/security/advisories/GHSA-jp6g-796f-39vp
Affected products (1)
- cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:*
More vulnerabilities in Cesanta Mongoose
- CVE-2022-25299 — Critical (CVSS 9.8): This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using…
- CVE-2020-25756 — Critical (CVSS 9.8): A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of…
- CVE-2019-19307 — Critical (CVSS 9.8): An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS…
- CVE-2019-12951 — Critical (CVSS 9.8): An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based…
- CVE-2018-20356 — Critical (CVSS 9.8): An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in…
- CVE-2018-20355 — Critical (CVSS 9.8): An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in…
All CVEs affecting Cesanta Mongoose →
Other CWE-295 (Improper Certificate Validation) vulnerabilities
- CVE-2026-58162 — Critical (CVSS 10.0): The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This…
- CVE-2026-4370 — Critical (CVSS 10.0): A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the…
- CVE-2026-30836 — Critical (CVSS 10.0): Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6…
- CVE-2025-68121 — Critical (CVSS 10.0): During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between…
- CVE-2022-20703 — Critical (CVSS 10.0): Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker…
- CVE-2026-78234 — Critical (CVSS 9.9): A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the…
Browse all CWE-295 (Improper Certificate Validation) vulnerabilities →