Loading market data...
← Back to CVE feed

CVE-2026-73064

LOW CVSS 2.9 View on NVD ↗

Description

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Published: Sep 24, 2026 15:17 UTC Modified: Sep 24, 2026 21:04 UTC