CVE-2026-25835
Mbed TLS vulnerability analysis and mitigation

Overview

CVE-2026-25835 is a PRNG seed misuse vulnerability in Mbed TLS and TF-PSA-Crypto that enables predictable random number generation, compromising cryptographic operations. It affects Mbed TLS versions 2.18.0 through 3.6.5 and version 4.0.0, as well as TF-PSA-Crypto versions prior to 1.1.0. The vulnerability was published on April 1, 2026, with patches available in Mbed TLS 3.6.6 and TF-PSA-Crypto 1.1.0. It carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory, Mbed TLS Advisory).

Technical details

The root cause is classified as CWE-335 (Incorrect Usage of Seeds in Pseudo-Random Number Generator), where the PRNG does not correctly manage seeds, resulting in predictable output. The attack vector is local (AV:L) with low complexity and no privileges or user interaction required, meaning any local process or user on the affected system could potentially exploit the flaw. When seeds are misused or reused improperly, an attacker with local access can observe or predict PRNG output, undermining the randomness guarantees that cryptographic key generation, nonce creation, and other security-sensitive operations depend upon. The official security advisory provides further technical context (Mbed TLS Advisory, GitHub Advisory).

Impact

Successful exploitation could allow local attackers to forge cryptographic keys, decrypt sensitive data, or manipulate encrypted communications by predicting PRNG output. The vulnerability has high confidentiality and integrity impact with no availability impact, meaning an attacker could silently compromise cryptographic material without causing service disruption. Given that Mbed TLS is widely used in embedded systems, IoT devices, and security-critical applications, the scope of affected assets is broad, and compromise of PRNG output could enable downstream attacks such as session hijacking or private key recovery (GitHub Advisory, Mbed TLS Advisory).

Mitigation and workarounds

Organizations should upgrade Mbed TLS to version 3.6.6 or later (for the 2.x/3.x branch), apply the latest available patch for Mbed TLS 4.0.0, and upgrade TF-PSA-Crypto to version 1.1.0 or later. After patching, validate that PRNG functionality operates correctly in dependent applications. Downstream distributions including SUSE and Fedora have issued updated packages incorporating the fix (Mbed TLS Advisory, SUSE Advisory).

Community reactions

The vulnerability received coverage from standard security aggregators including VulDB, CVEFeed, and ENISA's EUVD (EUVD-2026-17999). Downstream Linux distributions including SUSE, openSUSE, and Fedora issued security updates incorporating the fix, indicating broad ecosystem awareness. A Mastodon post from @thehackerwire noted the disclosure shortly after publication. No significant researcher controversy or vendor dispute has been observed (SUSE Advisory, openSUSE Announce).

Additional resources


SourceThis report was generated using AI

Related Mbed TLS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54441NONEN/A
  • Mbed TLS logoMbed TLS
  • mbedtls-doc
NoYesJul 23, 2026
CVE-2026-54435NONEN/A
  • Mbed TLS logoMbed TLS
  • mbedtls-doc
NoYesJul 23, 2026
CVE-2026-50713NONEN/A
  • Mbed TLS logoMbed TLS
  • mbedtls
NoYesJul 23, 2026
CVE-2026-50640NONEN/A
  • Mbed TLS logoMbed TLS
  • mbedtls-debuginfo
NoYesJul 23, 2026
CVE-2026-50588NONEN/A
  • Mbed TLS logoMbed TLS
  • mbedtls-debuginfo
NoYesJul 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management