๐Ÿ” CVE Alert

CVE-2026-73253

UNKNOWN 0.0

Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_cert_san() and mg_tls_verify_cert_cn() functions in src/tls_builtin.c call mg_match(), whose wildcard can cross DNS label boundaries, so a pattern such as *.example.com can match foo.bar.example.com. The resulting hostname verification bypass permits interception and modification of TLS traffic. This issue is fixed in version 7.22.

CWE CWE-295
Vendor cesanta
Product mongoose
Published Aug 20, 2026
Last Updated Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for cesanta mongoose

Be the first to know when new unknown vulnerabilities affecting cesanta mongoose are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

cesanta / mongoose
< 7.22

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cesanta/mongoose/security/advisories/GHSA-jp6g-796f-39vp github.com: https://github.com/cesanta/mongoose/pull/3611 github.com: https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71 github.com: https://github.com/cesanta/mongoose/releases/tag/7.22