CVE-2025-27810: Arm Mbed TLS

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

Affected products

  • Arm Mbed TLS: before 2.28.10 (fixed in 2.28.10)
  • Trustedfirmware Mbed TLS: from 3.0.0, before 3.6.3 (fixed in 3.6.3)

Published 2025-03-25. Last modified 2026-06-17.