CVE-2026-34873 Details
Description
An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.
A client impersonation vulnerability has been identified in Mbed TLS versions 3.5.0 prior to 3.6.6 and 4.0.0. The issue arises when a server capable of both TLS 1.2 and TLS 1.3 is requested to resume a TLS 1.3 session using a ticket. If the server responds with a HelloRetryRequest and the subsequent ClientHello negotiates TLS 1.2, the server incorrectly resumes a TLS 1.2 session using an all-zero master secret. This flaw allows a man-in-the-middle attacker to intercept the HelloRetryRequest and complete the handshake as if they were a legitimate client, potentially bypassing authentication mechanisms and inheriting application-level privileges encoded in the session ticket.
Users of Mbed TLS 3.6 LTS should upgrade to 3.6.6 or later. Users of the 4.x series should upgrade to 4.1.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| trustedfirmware mbed tls | >= 3.5.0, < 3.6.6 >= 4.0.0, < 4.1.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | CPE Deprecation Remap | [email protected] |
| Jun 5, 2026 | CPE Deprecation Remap | [email protected] |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Apr 2, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | New CVE Received | [email protected] |