TLS Stream Integrity Flaw in Mbed TLS by Arm
CVE-2026-73064
2.9LOW
What is CVE-2026-73064?
A vulnerability in Mbed TLS versions 3.2.0 through 3.6.6 and 4.0.0 through 4.1.0 allows an attacker to manipulate the TLS stream by causing an entropy source to fail. This flaw specifically affects TLS 1.3 servers, enabling potential injection or removal of bytes at the start of the stream, which could compromise the integrity of encrypted communications.
Affected Version(s)
Mbed TLS 3.2.0 < 3.6.7
Mbed TLS 4.0.0 < 4.1.1
