CVE-2026-34875
Mbed TLS vulnerability analysis and mitigation

Overview

CVE-2026-34875 is a critical buffer overflow vulnerability affecting Mbed TLS through version 3.6.5 and TF-PSA-Crypto 1.0.0, occurring during public key export for Finite Field Diffie-Hellman (FFDH) keys. It affects Mbed TLS versions 3.5.0 through 3.6.5 and TF-PSA-Crypto versions prior to 1.1.0, from both ARM and Trusted Firmware project distributions. The vulnerability was published on April 1, 2026, and has a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Mbed TLS Advisory).

Technical details

The vulnerability is classified as CWE-120 (Buffer Copy without Checking Size of Input — Classic Buffer Overflow), stemming from improper buffer size validation during the export process of FFDH public keys. When an application calls the public key export function for FFDH keys, insufficient bounds checking allows data to be written beyond the allocated buffer boundary, resulting in memory corruption. The flaw is exploitable remotely with no authentication or user interaction required, given that FFDH key operations can be triggered through network-facing cryptographic handshakes (GitHub Advisory, Mbed TLS Advisory).

Impact

Successful exploitation of this vulnerability can result in memory corruption that may lead to arbitrary code execution, denial of service, or disclosure of sensitive information, affecting confidentiality, integrity, and availability at a high level. Because the vulnerability is reachable over the network without authentication, any system exposing a service that uses Mbed TLS or TF-PSA-Crypto for FFDH key operations is at risk of full compromise. Attackers could potentially leverage code execution to pivot laterally within a network or exfiltrate cryptographic material (GitHub Advisory, Mbed TLS Advisory).

Mitigation and workarounds

Users should upgrade Mbed TLS to version 3.6.6 or later, and TF-PSA-Crypto to version 1.1.0 or later to remediate this vulnerability. Organizations unable to patch immediately should audit and restrict network exposure of services relying on FFDH key operations and monitor for anomalous cryptographic operation behavior. Patch details and guidance are available on the official Mbed TLS security advisories page (Mbed TLS Advisory, GitHub Advisory).

Community reactions

The vulnerability received coverage from security news outlets including The Hacker Wire shortly after disclosure, and was noted in the openSUSE security announcement mailing list as part of downstream package updates. FreeBSD also issued a VuXML entry for the affected packages. Community discussion was limited, with no major researcher commentary or significant social media debate observed beyond routine CVE tracking (Mbed TLS Advisory).

Additional resources


SourceThis report was generated using AI

Related Mbed TLS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54441NONEN/A
  • Mbed TLS logoMbed TLS
  • mbedtls-doc
NoYesJul 23, 2026
CVE-2026-54435NONEN/A
  • Mbed TLS logoMbed TLS
  • mbedtls-doc
NoYesJul 23, 2026
CVE-2026-50713NONEN/A
  • Mbed TLS logoMbed TLS
  • mbedtls
NoYesJul 23, 2026
CVE-2026-50640NONEN/A
  • Mbed TLS logoMbed TLS
  • mbedtls-debuginfo
NoYesJul 23, 2026
CVE-2026-50588NONEN/A
  • Mbed TLS logoMbed TLS
  • mbedtls-debuginfo
NoYesJul 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management