[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-73251":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-20T15:42:44.608Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":27,"aliases":28,"duplicate_of":9,"upstream":30,"downstream":31,"duplicates":32,"related":33,"reserved_at":9,"published_at":34,"modified_at":34,"state":35,"summary":36,"references_raw":43,"kevs":65,"epss":9,"epss_history":66,"metrics":67,"affected":74},"CVE-2026-73251","Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function stores the bundle in tls->ca_bundle_der while tls->ca_der.len remains zero, and mg_tls_recv_cert() uses tls_bundle_find() to accept a Common Name match without calling mg_tls_verify_cert_signature(). A forged self-signed certificate can therefore satisfy hostname and CertificateVerify checks and enable interception, credential disclosure, traffic modification, and malicious responses. This issue is fixed in version 7.23.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-295","Improper Certificate Validation","The product does not validate, or incorrectly validates, a certificate.","weakness","Draft","Base",[19,23],{"id":20,"name":21,"techniques":22},"CAPEC-459","Creating a Rogue Certification Authority Certificate",[],{"id":24,"name":25,"techniques":26},"CAPEC-475","Signature Spoofing by Improper Validation",[],[],[29],"DEBIAN-CVE-2026-73251",[],[],[],[],"2026-08-20T17:34:50.472Z","Received",{"cisa_kev":37,"cisa_ransomware":37,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":38,"severity_score":39,"severity_version":40,"severity_source":41,"severity_vector":42,"severity_status":35},false,"critical",9.3,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",[44,50,56,61],{"url":45,"sources":46,"tags":48},"https://security-tracker.debian.org/tracker/CVE-2026-73251",[47],"osv_debian",[49],"Advisory",{"url":51,"sources":52,"tags":54},"https://github.com/cesanta/mongoose/security/advisories/GHSA-qj6j-2692-v2r8",[41,53],"nvd",[55],"X Refsource CONFIRM",{"url":57,"sources":58,"tags":59},"https://github.com/cesanta/mongoose/commit/2988bc9df3a5efc9539471cb7455975fa25df483",[41,53],[60],"X Refsource MISC",{"url":62,"sources":63,"tags":64},"https://github.com/cesanta/mongoose/releases/tag/7.23",[41,53],[60],[],[],[68,71],{"source":41,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":69},{"baseScore":39,"baseSeverity":70,"vectorString":42,"impactScore":9,"exploitabilityScore":9},"CRITICAL",{"source":53,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":72},{"baseScore":39,"baseSeverity":70,"vectorString":73,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[75,85],{"ecosystem":9,"name":76,"vendor":77,"product":76,"cpe_part":78,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":79},"mongoose","cesanta","a",[80],{"version":81,"is_range":82,"range_type":41,"version_start":9,"version_start_type":9,"version_end":83,"version_end_type":84,"fixed_in":9},"\u003C 7.23",true,"7.23","excluding",{"ecosystem":86,"name":76,"vendor":87,"product":76,"cpe_part":9,"purl_type":88,"purl_namespace":87,"purl_name":76,"source":9,"versions":89},"Debian","debian","deb",[90,93],{"version":91,"is_range":82,"range_type":92,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"all","ecosystem",{"version":94,"is_range":82,"range_type":92,"version_start":9,"version_start_type":9,"version_end":95,"version_end_type":84,"fixed_in":9},"lt7_23+ds_1","7.23+ds-1"]