CVE Watchtower

← Back to CVE List

CVE-2026-25832NVD

Description

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
Severity Level
LOW (3.7)
Published Date
14/09/2026
Last Modified
14/09/2026
Exploitation Status
????
EPSS Score
0.22% (percentile 12.5%)

CVSS Base Metrics

CVSS v3 (3.1)
LOW 3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses (CWE)

CWE-669 - CWE-669 Incorrect Resource Transfer Between Spheres

Affected & Patched Versions

ProductAffected VersionsPatched Version
TrustedFirmware Mbed TLS3.5.0 - < 3.6.7, 4.0.0 - < 4.1.2N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.