Out-of-bounds read in Mongoose - CVE-2026-73260
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the built-in TLS X.509 DER parser when parsing a crafted X.509 certificate during the TLS handshake. A remote attacker can present a specially crafted certificate to cause a denial of service.
Only applications built with the built-in TLS stack are vulnerable, and exploitation occurs before authentication completes.