CVE-2026-34875 is a critical buffer overflow vulnerability affecting Mbed TLS through version 3.6.5 and TF-PSA-Crypto 1.0.0, specifically occurring during public key export for FFDH keys. Rated 9.8 CRITICAL, this vulnerability allows unauthenticated attackers to achieve high confidentiality, integrity, and availability impacts over the network with low attack complexity. While not currently listed on the CISA KEV catalog or having public exploit code, it is on the "Hot List: Active" and has garnered some community discussion, indicating potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.5.0, < 3.6.6CPE matchmatch criteria | cpe:2.3:a:trustedfirmware:mbed_tls:*:*:*:*:*:*:*:* | ||
< 1.1.0CPE matchmatch criteria | cpe:2.3:a:trustedfirmware:tf-psa-crypto:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.