Logo
vulnerabilityCVE-2026-34872
Name
CVE-2026-34872
Source
NVD ( link)Debian ( link)
Description
An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
mbedtls
Exploitable
mbedtls
Exploitable

Vulnerability Ratings#


9.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.6.6
Not Affected
buildroot
master
3.6.6
Not Affected
openwrt
master
3.6.6-r2
Not Affected
openwrt
openwrt-25.12
3.6.6-r2
Not Affected
yocto
kirkstone
2.28.10
Exploitable
yocto
master
3.6.6
Not Affected