← All CVEs

CVE-2026-34877

critical · 9.8

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.

9.8
CVSS
0.4%
EPSS (exploit prob.)
37th
EPSS percentile
2026-04-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-250CWE-502

Affected products

VendorProductAffected versions
armmbed_tls>= 2.19.0, < 3.6.6
trustedfirmwarembed_tls4.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-34877