VYPR
High severity7.7NVD Advisory· Published Apr 1, 2026· Updated Apr 6, 2026

CVE-2026-25835

CVE-2026-25835

Description

Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).

Affected products

3
  • Arm/Mbed Tls2 versions
    cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*range: >=2.18.0,<3.6.6
    • cpe:2.3:a:arm:mbed_tls:4.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:arm:tf-psa-crypto:*:*:*:*:*:*:*:*
    Range: <1.1.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.