CVE-2026-34877

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:mbed_tls:4.0.0:*:*:*:*:*:*:*

History

06 Apr 2026, 21:06

Type Values Removed Values Added
References () https://mbed-tls.readthedocs.io/en/latest/security-advisories/ - () https://mbed-tls.readthedocs.io/en/latest/security-advisories/ - Vendor Advisory
References () https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-serialized-data/ - () https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-serialized-data/ - Vendor Advisory
CPE cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:mbed_tls:4.0.0:*:*:*:*:*:*:*
First Time Arm
Arm mbed Tls

02 Apr 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-250
CWE-502

02 Apr 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 17:16

Updated : 2026-04-06 21:06


NVD link : CVE-2026-34877

Mitre link : CVE-2026-34877

CVE.ORG link : CVE-2026-34877


JSON object : View

Products Affected

arm

  • mbed_tls
CWE
CWE-250

Execution with Unnecessary Privileges

CWE-502

Deserialization of Untrusted Data