CVE-2026-25832: Low severity Mbed TLS Mbed TLS vulnerability
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using Mbed TLS as a TLS 1.3 client are affected if they run Mbed TLS 3.6.x before 3.6.7 or 4.1.x before 4.1.2. The issue concerns processing of HelloRetryRequest messages.
What does exploitation require?
The vulnerability is network-reachable and requires no privileges or user interaction, but it has high attack complexity. Exploitation depends on getting the client to accept a HelloRetryRequest that selects a group the client did not advertise.
What should be done to remediate it?
Upgrade Mbed TLS 3.6.x to 3.6.7 or later, or upgrade Mbed TLS 4.1.x to 4.1.2 or later.
How can I determine whether an instance is exposed?
Check the deployed Mbed TLS version and whether the application operates as a TLS 1.3 client. Versions earlier than 3.6.7 in the 3.6.x line and earlier than 4.1.2 in the 4.1.x line are affected.