Mongoose: Preauth RCE and MTLS Bypass on Devices(evilsocket.net)
evilsocket.net
Mongoose: Preauth RCE and MTLS Bypass on Devices
https://www.evilsocket.net/2026/04/02/Mongoose-Preauth-Remote-Code-Execution-and-mTLS-Bypass/
https://www.evilsocket.net/2026/04/02/Mongoose-Preauth-Remote-Code-Execution-and-mTLS-Bypass/
CVE-2026-5244 - mg_tls_recv_cert pubkey heap-based overflow (exploitable), CVE-2026-5245 - mDNS Record stack-based overflow (exploitable), CVE-2026-5246 - authorization bypass via P-384 Public Key (trivially exploitable)
Fun ride.