Executive brief
Mongoose is an embedded web server and network library used in IoT and embedded systems. Prior to version 7.23, an attacker on the network can impersonate a legitimate TLS server by forging a self-signed certificate when Mongoose is configured with a multi-certificate CA bundle. This allows attackers to intercept encrypted connections, steal credentials, modify traffic, and inject malicious responses without detection.
Technical details
The vulnerability is a TLS certificate verification bypass in the built-in TLS implementation. When mg_tls_init() loads a multi-certificate CA bundle, it stores the bundle in tls->ca_bundle_der but leaves tls->ca_der.len at zero. The mg_tls_recv_cert() function then uses tls_bundle_find() to match certificates by Common Name without calling mg_tls_verify_cert_signature(), allowing a forged self-signed certificate to pass hostname verification and CertificateVerify checks. The attack requires network position to intercept TLS connections but no authentication or user interaction. An attacker can perform man-in-the-middle attacks to intercept, eavesdrop on, and modify encrypted communications. The vulnerability is fixed in Mongoose 7.23.
Affected products
- Cesanta Mongoose prior to 7.23
Timeline
- 2026-08-20: disclosed
- 2026-08-12: patched: Fixed in version 7.23