
CVE-2026-1677 Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol … https://www.cve.org/CVERecord?id=CVE-2026-1677
Post summary
The post discloses that Zephyr sockets may downgrade from TLS 1.3 to TLS 1.2 when both versions are enabled, revealing a protocol downgrade flaw.

