CVE-2026-34872 Details
Description
An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).
A vulnerability exists in Mbed TLS versions 3.5.x and 3.6.x prior to 3.6.5, as well as in TF-PSA-Crypto 1.0. The issue arises from improper input validation in finite-field Diffie-Hellman (FFDH) key agreement, allowing a peer to manipulate the shared secret into a limited range of values. This lack of contributory behavior could be problematic for certain protocols that rely on it, although TLS 1.3 is not affected due to its handshake mechanics. The vulnerability can be exploited by the peer or, in some protocols, by an active network attacker.
Users should upgrade to Mbed TLS 3.6.6 or later, or TF-PSA-Crypto 1.1.0 or later. For those maintaining branches with backported bug fixes, relevant commits are available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://mbed-tls.readthedocs.io/en/latest/security-advisories/ | [email protected] | Vendor Advisory |
| https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-ffdh-peerkey-checks/ | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| arm mbed tls | < 3.6.6 |
CPE
Remediation
| |
| arm tf-psa-crypto | 1.0.0 - |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |
| Apr 1, 2026 | CVE Modified | CISA-ADP |