HackerFeeds
All CVEs

CVE-2026-73064

LOW2.9

Published 2026-09-24 · Updated 2026-09-24 · Source cve@mitre.org

Description

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.

CVSS vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CWE-394
View on NVD