CVE-2025-59438: Medium severity Mbed TLS Mbed TLS vulnerability
Published Oct 21, 2025
·Updated
Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.
Affected Software
2 affected components
Mbed TLS Mbed TLS<=3.6.4
Arm mbed TLS<3.6.5
Event History
Oct 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59438?
CVE-2025-59438 has been classified with a medium severity level due to the potential for timing attacks.
2
How do I fix CVE-2025-59438?
To address CVE-2025-59438, upgrade Mbed TLS to version 3.6.5 or later immediately.
3
What is an Observable Timing Discrepancy in CVE-2025-59438?
An Observable Timing Discrepancy allows an attacker to potentially exploit timing variations to gain insights into sensitive data.
4
Is CVE-2025-59438 present in all versions of Mbed TLS?
CVE-2025-59438 affects Mbed TLS versions up to and including 3.6.4.
5
Are there any workarounds for CVE-2025-59438 if I can't upgrade?
Currently, the best mitigation for CVE-2025-59438 is to upgrade the affected version, as no reliable workarounds are available.