CVE-2026-73064
Received
Received - Intake
Mbed TLS TLS 1.3 Server Entropy Source Manipulation
Vulnerability report for CVE-2026-73064, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-24
Last updated on: 2026-09-24
Assigner: MITRE
Description
Description
In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mbed_tls | mbedtls | From 3.2.0 (inc) to 3.6.6 (inc) |
| mbed_tls | mbedtls | From 4.0.0 (inc) to 4.1.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-394 | The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product. |