CVE-2026-34873

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

critical 9.1 CVSS 3.1
Published: Apr 1, 2026
Modified: Jun 5, 2026
Vendor: Trustedfirmware
Product: Mbed Tls

Description

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

References

Related CVEs