Low severity3.7NVD Advisory· Published Sep 14, 2026
CVE-2026-25832
CVE-2026-25832
Description
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/mbedtls&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls-3&distro=openSUSE%20Tumbleweed
< 4.2.0-1.1+ 1 more
- (no CPE)range: < 4.2.0-1.1
- (no CPE)range: < 3.6.7-1.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.