Known Vulnerabilities for Mbed by Arm
Listed below are 1 of the newest known vulnerabilities associated with "Mbed" by "Arm".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34877 | An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized S... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-34876 | An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-34875 | An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export f... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-34874 | An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-34873 | An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. | Not Provided | 2026-04-01 | 2026-04-02 |
| CVE-2026-34872 | An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory beha... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-34871 | An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable ... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-25835 | Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-25834 | Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade. | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-25833 | Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function | Not Provided | 2026-04-01 | 2026-04-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Arm | Mbed | 5.9.7 | All | All | All |
| Operating System | Arm | Mbed | 5.9.6 | All | All | All |
| Operating System | Arm | Mbed | 5.9.5 | All | All | All |
| Operating System | Arm | Mbed | 5.9.4 | All | All | All |
| Operating System | Arm | Mbed | 5.9.3 | All | All | All |
| Operating System | Arm | Mbed | 5.9.2 | All | All | All |
| Operating System | Arm | Mbed | 5.9.1 | All | All | All |
| Operating System | Arm | Mbed | 5.9.0 | - | All | All |
| Operating System | Arm | Mbed | 5.9.0 | rc1 | All | All |
| Operating System | Arm | Mbed | 5.9.0 | rc2 | All | All |
| Operating System | Arm | Mbed | 5.9.0 | rc3 | All | All |
| Operating System | Arm | Mbed | 5.8.6 | All | All | All |
| Operating System | Arm | Mbed | 5.8.5 | All | All | All |
| Operating System | Arm | Mbed | 5.8.4 | All | All | All |
| Operating System | Arm | Mbed | 5.8.3 | All | All | All |
| Operating System | Arm | Mbed | 5.8.2 | All | All | All |
| Operating System | Arm | Mbed | 5.8.1 | All | All | All |
| Operating System | Arm | Mbed | 5.8.0 | - | All | All |
| Operating System | Arm | Mbed | 5.8.0 | rc1 | All | All |
| Operating System | Arm | Mbed | 5.8.0 | rc2 | All | All |