CVE-2026-34877

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
cpe:2.3:a:trustedfirmware:mbed_tls:4.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-02 17:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-34877

Mitre link : CVE-2026-34877

CVE.ORG link : CVE-2026-34877


JSON object : View

Products Affected

trustedfirmware

  • mbed_tls

arm

  • mbed_tls
CWE
CWE-250

Execution with Unnecessary Privileges

CWE-502

Deserialization of Untrusted Data