CVE-2026-34872 is a critical vulnerability affecting Mbed TLS versions 3.5.x, 3.6.x through 3.6.5, and TF-PSA-Crypto 1.0. This flaw, rated 9.1 Critical, is due to improper input validation in Finite-Field Diffie-Hellman (FFDH), allowing an attacker to force the shared secret into a small set of values, impacting confidentiality and integrity. The vulnerability is network-exploitable with low attack complexity and can be leveraged by a peer or an active network attacker, though protocols like TLS are not dependent on the affected contributory behavior. There is currently no evidence of active exploitation, public exploit code, or significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.6CPE matchmatch criteria | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:arm:tf-psa-crypto:1.0.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.