CVE-2026-25832
Received Received - Intake

TLS 1.3 Client Accepts Unadvertised Group in Mbed TLS

Vulnerability report for CVE-2026-25832, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mbed_tls mbed_tls to 3.6.7 (exc)
mbed_tls mbed_tls to 4.1.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-669 The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability occurs in Mbed TLS versions 3.6.x before 3.6.7 and 4.1.x before 4.1.2. A TLS 1.3 client incorrectly accepts a HelloRetryRequest that selects an elliptic curve group not listed in the client's supported groups extension. This allows the client to proceed with a group it did not originally agree to use, potentially weakening the security of the key exchange process.

Detection Guidance

To detect this vulnerability, inspect TLS 1.3 handshake logs for HelloRetryRequest messages selecting unadvertised elliptic curve groups. Use packet capture tools like Wireshark to analyze TLS extensions and supported groups in ClientHello and HelloRetryRequest messages.

Impact Analysis

This vulnerability may affect the integrity and confidentiality of the TLS session if exploited. It could allow an attacker to manipulate the key exchange process, potentially leading to unauthorized access or data exposure during secure communications.

Mitigation Strategies

Upgrade Mbed TLS to version 3.6.7 or later for 3.6.x branch, or 4.1.2 or later for 4.1.x branch. Review and update TLS 1.3 client configurations to ensure advertised groups match intended security policies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25832. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart