VYPR
High severity7.5NVD Advisory· Published Apr 1, 2026· Updated Apr 3, 2026

CVE-2026-34874

CVE-2026-34874

Description

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.

Affected products

2
  • Arm/Mbed Tls2 versions
    cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*range: >=3.5.0,<3.6.6
    • cpe:2.3:a:arm:mbed_tls:4.0.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.