CVE-2026-73064

Summary

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.

Affected Software

VendorProductVersion RangeStatus
trustedfirmwareMbed TLS3.2.0 < 3.6.7affected
trustedfirmwareMbed TLS4.0.0 < 4.1.1affected

Weaknesses

  • CWE-394: CWE-394 Unexpected Status Code or Return Value

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References