Skip to main content

Vendor/product archive

arm / mbed_tls CVEs

Beta · best-effort

51 CVEs tagged to arm / mbed_tls8 Critical, 18 High, 25 Medium, 0 Low, 0 Unrated.

CVE-2026-34877

Published Apr 2, 2026

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker wh…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-34872

Published Apr 1, 2026

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using f…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-66442

Published Apr 1, 2026

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto thro…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34871

Published Apr 1, 2026

An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).

CVSS 6.7 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-54764

Published Oct 20, 2025

Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47917

Published Jul 20, 2025

Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_na…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48965

Published Jul 20, 2025

Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52497

Published Jul 4, 2025

Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52496

Published Jul 4, 2025

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program,…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27810

Published Mar 25, 2025

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, po…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27809

Published Mar 25, 2025

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mb…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23775

Published Jan 31, 2024

Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52353

Published Jan 21, 2024

An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated T…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36647

Published Jan 17, 2023

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attacke…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43666

Published Mar 24, 2022

A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45451

Published Dec 21, 2021

In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted applicat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 51 CVEsPage 1 of 3