CVE-2026-25832: Trustedfirmware Mbed TLS

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

Affected products

  • Trustedfirmware Mbed TLS: from 3.5.0, before 3.6.7 (fixed in 3.6.7); from 4.0.0, before 4.1.2 (fixed in 4.1.2)

Published 2026-09-14. Last modified 2026-09-22.