Mbed tls
This hub aggregates every CVE we track for Mbed tls, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
73
CVEs tracked
15
Critical
24
High
0
In CISA KEV
Severity distribution
MEDIUM34HIGH24CRITICAL15
Monthly trend
0
0
3
1
0
0
0
0
2
0
0
0
7
0
0
2
0
0
0
0
0
11
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Mbed tls.
- CVE-2026-34876An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocatio...7.5
- CVE-2026-34877An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the s...9.8
- CVE-2026-34871An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).6.7
- CVE-2026-34875An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.9.8
- CVE-2026-34874An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.7.5
- CVE-2026-34872An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie...9.1
- CVE-2026-34873An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.9.1
- CVE-2026-25833Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function7.5
- CVE-2026-25834Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.6.5
- CVE-2026-25835Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).7.7
- CVE-2025-66442In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also ...5.1
- CVE-2025-59438Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.5.3
- CVE-2025-54764Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.6.2
- CVE-2025-47917Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head...8.9
- CVE-2025-49087In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.4.0
Product normalization is registry-driven with AI assist and human review. How it works