Medium severity4.0NVD Advisory· Published Jul 20, 2025· Updated Jun 17, 2026
CVE-2025-49087
CVE-2025-49087
Description
In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Mbed/mbedtlsv5Range: 3.6.1
Patches
Vulnerability mechanics
References
2- github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-5.mdnvdExploitThird Party Advisory
- mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/nvdVendor Advisory
News mentions
0No linked articles in our index yet.