TLS 1.3 Client Vulnerability in Mbed TLS by Arm
CVE-2026-25832

3.7LOW

Key Information:

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-25832?

In the affected versions of Mbed TLS, the TLS 1.3 client is vulnerable to a flaw during the HelloRetryRequest phase, allowing it to select an unadvertised group. This can introduce potential security risks in communications, as the client may be manipulated into accepting configurations that were not properly advertised by the server, leading to possible exploits in secure data exchanges.

Affected Version(s)

Mbed TLS 3.5.0 < 3.6.7

Mbed TLS 4.0.0 < 4.1.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.