CVE-2025-27809: Arm Mbed TLS
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
Affected products
- Arm Mbed TLS: before 2.28.10 (fixed in 2.28.10)
- Trustedfirmware Mbed TLS: from 3.0.0, before 3.6.3 (fixed in 3.6.3)
Published 2025-03-25. Last modified 2026-06-17.