
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25834 is an algorithm downgrade vulnerability in Mbed TLS that allows network-based attackers to force weaker cryptographic algorithms during TLS negotiations. It affects Mbed TLS versions 3.3.0 through 3.6.5 and version 4.0.0, maintained by both Arm and Trusted Firmware. The vulnerability was published on April 1, 2026, and has been analyzed by NVD. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Mbed TLS Advisory).
The vulnerability is classified under CWE-295 (Improper Certificate Validation) and CWE-327 (Use of a Broken or Risky Cryptographic Algorithm), and is specifically described as a signature algorithm injection issue. An unauthenticated, network-adjacent attacker can manipulate TLS handshake negotiations to downgrade the cryptographic algorithm selected, bypassing stronger algorithm enforcement. The official Mbed TLS security advisory references this as a "sigalg injection" flaw, suggesting the attack involves injecting or manipulating the signature algorithm fields during the TLS handshake. No public proof-of-concept code has been identified at this time (GitHub Advisory, Mbed TLS Advisory).
Successful exploitation enables man-in-the-middle attackers to force TLS connections to use weaker cryptographic algorithms, potentially allowing decryption of communications that would otherwise be protected by stronger ciphers. The primary impacts are to integrity (low) and availability (low) of encrypted connections, with no direct confidentiality impact assessed in the CVSS score, though downgraded encryption could indirectly expose sensitive data over time. Affected deployments include any system using Mbed TLS 3.3.0–3.6.5 or 4.0.0 for TLS communications, including embedded systems, IoT devices, and server applications relying on this library (GitHub Advisory, Mbed TLS Advisory).
The primary remediation is to upgrade Mbed TLS to version 3.6.6 or later for the 3.x branch, or to the patched 4.0.0 release. Organizations should audit all deployments for instances running vulnerable versions (3.3.0–3.6.5 and 4.0.0) and prioritize patching in internet-facing or sensitive environments. Refer to the official Mbed TLS security advisories for specific patching guidance and any available configuration-based mitigations (Mbed TLS Advisory, Mbed TLS Advisories).
The vulnerability has been picked up by downstream Linux distributions including SUSE and openSUSE, which have issued security announcements and package updates. FreeBSD and Fedora package maintainers have also published updates addressing this CVE. Splunk issued an advisory (SVD-2026-0512) referencing this vulnerability in the context of their products. Coverage has been relatively low-key given the moderate severity rating and absence of active exploitation (SUSE Advisory, openSUSE Announce, Splunk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."