Unrated severityNVD Advisory· Published Jul 20, 2025· Updated Jul 21, 2025
CVE-2025-49087
CVE-2025-49087
Description
In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.
Affected products
1- Mbed/mbedtlsv5Range: 3.6.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.