TLS Stream Integrity Flaw in Mbed TLS by Arm
CVE-2026-73064

2.9LOW

Key Information:

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-73064?

A vulnerability in Mbed TLS versions 3.2.0 through 3.6.6 and 4.0.0 through 4.1.0 allows an attacker to manipulate the TLS stream by causing an entropy source to fail. This flaw specifically affects TLS 1.3 servers, enabling potential injection or removal of bytes at the start of the stream, which could compromise the integrity of encrypted communications.

Affected Version(s)

Mbed TLS 3.2.0 < 3.6.7

Mbed TLS 4.0.0 < 4.1.1

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.