CVE Tools

Mbed Tls

75 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Mbed Tls, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Mbed Tls CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Mbed Tls CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-032
2025-040
2025-050
2025-060
2025-077
2025-080
2025-090
2025-102
2025-110
2025-120
2026-010
2026-020
2026-030
2026-0411
2026-050
2026-060
2026-070
2026-080
2026-092

Severity

How the 75 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1520%
  • High2432%
  • Medium3445%
  • Low23%

Latest CVEs

The 15 most recently published vulnerabilities affecting Mbed Tls.

  1. CVE-2026-73064In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 se...2.9
  2. CVE-2026-25832In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.3.7
  3. CVE-2026-34877An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the s...9.8
  4. CVE-2026-34876An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocatio...7.5
  5. CVE-2026-34874An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.7.5
  6. CVE-2026-34871An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).6.7
  7. CVE-2026-34875An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.9.8
  8. CVE-2026-34873An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.9.1
  9. CVE-2026-34872An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie...9.1
  10. CVE-2026-25833Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function7.5
  11. CVE-2026-25834Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.6.5
  12. CVE-2026-25835Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).7.7
  13. CVE-2025-66442In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also ...5.1
  14. CVE-2025-59438Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.5.3
  15. CVE-2025-54764Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.6.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store