
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34875 is a critical buffer overflow vulnerability affecting Mbed TLS through version 3.6.5 and TF-PSA-Crypto 1.0.0, occurring during public key export for Finite Field Diffie-Hellman (FFDH) keys. It affects Mbed TLS versions 3.5.0 through 3.6.5 and TF-PSA-Crypto versions prior to 1.1.0, from both ARM and Trusted Firmware project distributions. The vulnerability was published on April 1, 2026, and has a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Mbed TLS Advisory).
The vulnerability is classified as CWE-120 (Buffer Copy without Checking Size of Input — Classic Buffer Overflow), stemming from improper buffer size validation during the export process of FFDH public keys. When an application calls the public key export function for FFDH keys, insufficient bounds checking allows data to be written beyond the allocated buffer boundary, resulting in memory corruption. The flaw is exploitable remotely with no authentication or user interaction required, given that FFDH key operations can be triggered through network-facing cryptographic handshakes (GitHub Advisory, Mbed TLS Advisory).
Successful exploitation of this vulnerability can result in memory corruption that may lead to arbitrary code execution, denial of service, or disclosure of sensitive information, affecting confidentiality, integrity, and availability at a high level. Because the vulnerability is reachable over the network without authentication, any system exposing a service that uses Mbed TLS or TF-PSA-Crypto for FFDH key operations is at risk of full compromise. Attackers could potentially leverage code execution to pivot laterally within a network or exfiltrate cryptographic material (GitHub Advisory, Mbed TLS Advisory).
Users should upgrade Mbed TLS to version 3.6.6 or later, and TF-PSA-Crypto to version 1.1.0 or later to remediate this vulnerability. Organizations unable to patch immediately should audit and restrict network exposure of services relying on FFDH key operations and monitor for anomalous cryptographic operation behavior. Patch details and guidance are available on the official Mbed TLS security advisories page (Mbed TLS Advisory, GitHub Advisory).
The vulnerability received coverage from security news outlets including The Hacker Wire shortly after disclosure, and was noted in the openSUSE security announcement mailing list as part of downstream package updates. FreeBSD also issued a VuXML entry for the affected packages. Community discussion was limited, with no major researcher commentary or significant social media debate observed beyond routine CVE tracking (Mbed TLS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."