Medium severity5.4NVD Advisory· Published Mar 25, 2025· Updated Jun 17, 2026
CVE-2025-27809
CVE-2025-27809
Description
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords3 versionspkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/mbedtls&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Tumbleweed
< 2.28.10-bp160.1.1+ 2 more
- (no CPE)range: < 2.28.10-bp160.1.1
- (no CPE)range: < 3.6.6-bp160.1.1
- (no CPE)range: < 2.28.10-1.1
- Mbed/mbedtlsv5Range: 0
Patches
Vulnerability mechanics
References
4- mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-03-1/nvdThird Party Advisory
- github.com/Mbed-TLS/mbedtls/issues/466nvdIssue Tracking
- github.com/Mbed-TLS/mbedtls/releasesnvdRelease Notes
- mastodon.social/@bagder/114219540623402700nvdNot Applicable
News mentions
0No linked articles in our index yet.