CVE-2026-25832
EUVD-2026-7730514.09.2026, 07:17
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| trustedfirmware | mbed_tls | 3.5.0 ≤ 𝑥 < 3.6.7 | CNA |
| trustedfirmware | mbed_tls | 4.0.0 ≤ 𝑥 < 4.1.2 | CNA |
Debian Releases
Ubuntu Releases