Junglewise Threat Intelligence

CVE-2026-73253: Mongoose wildcard certificate hostname verification bypass

CVE-2026-73253 · Severity: info · CVSS 6.5 · Published 2026-08-20

Vendors: Cesanta.

Executive brief

Mongoose is a lightweight embedded web server used in IoT devices, firmware, and networked applications. An attacker on the network path with a wildcard certificate for a parent domain can impersonate subdomains to client applications, allowing interception and modification of TLS-encrypted traffic. This breaks the security guarantee that connections are made to the intended server.

Technical details

The vulnerability is a hostname verification bypass in Mongoose's built-in TLS stack. The mg_tls_verify_cert_san() and mg_tls_verify_cert_cn() functions in src/tls_builtin.c use mg_match() to validate certificate hostnames, but the wildcard matching is overly permissive—allowing a pattern like *.example.com to incorrectly match foo.bar.example.com (crossing DNS label boundaries). An on-path network attacker with a wildcard certificate for a parent domain can exploit this to perform man-in-the-middle attacks against clients. The vulnerability requires network adjacency and does not require authentication or user interaction. The issue was fixed in version 7.22.

Affected products

  • Cesanta Mongoose before 7.22

Timeline

  • 2026-08-20: disclosed: CVE-2026-73253 published
  • 2026-06-23: patched: Fix committed to Mongoose master branch

References