
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34871 is a predictable seed vulnerability in the Pseudo-Random Number Generator (PRNG) of Mbed TLS and TF-PSA-Crypto. It affects Mbed TLS before version 3.6.6, Mbed TLS 4.x before 4.1.0, and TF-PSA-Crypto before 1.1.0. The vulnerability was published on April 1, 2026, and is classified as CWE-338 (Use of Cryptographically Weak PRNG). It carries a CVSS v3.1 base score of 6.7 (Medium) (GitHub Advisory, Mbed TLS Advisory).
The root cause is the use of a predictable seed when initializing the PRNG in Mbed TLS and TF-PSA-Crypto, classified under CWE-338 (Use of Cryptographically Weak Pseudo-Random Number Generator). Because the seed is predictable, an attacker with local access and sufficient knowledge of the system state can reconstruct or predict the PRNG output. This undermines the randomness guarantees required for cryptographic operations such as key generation and nonce creation. The attack vector is local with high complexity, requiring no privileges or user interaction (GitHub Advisory, Mbed TLS Advisory).
Successful exploitation allows an attacker with local access to predict PRNG output, potentially compromising cryptographic key generation and nonce generation within affected Mbed TLS or TF-PSA-Crypto deployments. This can lead to high confidentiality and integrity impacts — an attacker could recover sensitive cryptographic material (e.g., private keys) or forge authentication tokens, while availability is not directly affected. Systems that generated cryptographic keys or certificates using vulnerable versions may have weakened security even after patching, necessitating regeneration of that material (GitHub Advisory, Mbed TLS Advisory).
Vendors have released patches addressing this vulnerability. Organizations should upgrade to Mbed TLS 3.6.6 or later (for the 3.x branch), Mbed TLS 4.1.0 or later (for the 4.x branch), or TF-PSA-Crypto 1.1.0 or later. After patching, it is strongly recommended to regenerate any cryptographic material (keys, certificates, tokens) that was produced by vulnerable versions, as that material may have been generated with a predictable seed. Downstream distributions including openSUSE, Fedora, Debian LTS, and FreeBSD have also issued updated packages (Mbed TLS Advisory, Mbed TLS Security).
The vulnerability has been picked up by downstream Linux distributions including openSUSE, Fedora, Debian LTS, and FreeBSD, all of which have issued security updates. Splunk also published an advisory (SVD-2026-0512) referencing this CVE, indicating broader ecosystem impact. Coverage has been largely routine, with no notable researcher commentary or significant social media discussion beyond standard vulnerability tracking (openSUSE, Debian LTS, Splunk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."