CVE-2026-34875Disclosure(trustedfirmware / mbed_tls)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch trustedfirmware mbed_tls systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mbed_tls
  • tf-psa-crypto

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-02); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Products
mbed_tlstf-psa-crypto

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-01: 1Mentions · 2026-04-02: 2Mentions · 2026-05-18: 1Mentions · 2026-06-27: 1Mentions · 2026-07-02: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 2Technical Details · 2026-05-18: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-02: 104-0104-0205-1806-2707-02
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-011
Disclosure1
2026-04-022
Disclosure2
2026-05-181
Disclosure1
2026-06-271
Patch1
2026-07-021
Disclosure1
Full discourse6 posts
  • Haruto Kimura@harutosec
    Patch

    Memory corruption isn't theoretical. One that my pipeline found, verified, and shipped: CVE-2026-34875 — Arm Mbed TLS, CVSS 9.8. Missing buffer check in mbedtls_psa_ffdh_export_public_key() FFDH path → heap overflow. Sanitizer-proven, source-cited, then disclosed. Fixed in 3.6.6.

    Post summary

    A memory corruption CVE-2026-34875 in Arm Mbed TLS causes a heap overflow due to a missing buffer check, was verified via sanitizer, has a CVSS of 9.8, was disclosed, and is fixed in version 3.6.6.

    10050262
    23 followersView on X
  • Haruto Kimura@harutosec
    Disclosure

    The bug classes don't care how new the primitive is — fresh parsing and length-handling code in C reintroduces them every time. From my audits this year: wolfSSL ECH config parser (stack overflow, CVE-2026-3849), GnuTLS DTLS fragment reassembly (heap overflow, CVE-2026-33846), Mbed TLS FFDH export (heap overflow, CVE-2026-34875). PQ rollout means a lot of fresh C. The prediction sounds right.

    Post summary

    An analyst reports three newly discovered CVEs in TLS libraries, noting their overflow types, but offers no PoC, exploit, or patch details.

    00011161
    20 followersView on X
  • Okashira@harutosec
    Disclosure

    For instance, two CVEs passed every gate: CVE-2026-34875 — Mbed TLS, CVSS 9.8 Missing buffer check in psa_export_public_key() FFDH path. Stack overflow. CVE-2026-6766 — Mozilla NSS, CVSS 7.5 Unsigned underflow in tls13_AEAD → wild-pointer SEGV in QUIC. Paid by Mozilla.

    Post summary

    The message announces two newly identified high‑severity CVEs affecting Mbed TLS and Mozilla NSS, providing concise technical description and CVSS scores.

    10000136
    13 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-34875: CRITICAL] An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.#cve,CVE-2026-34875,#cybersecurity https://cvefind.com/CVE-2026-34875

    Post summary

    A critical buffer overflow in Mbed TLS 3.6.5 and TF-PSA-Crypto 1.0.0’s public key export for FFDH keys has been disclosed, but no PoC, tooling, exploitation in the wild, or fix is mentioned.

    0000032
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34875 - Critical An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. https://www.thehackerwire.com/vulnerability/CVE-2026-34875/ https://t.co/NjMrO9htfu

    Post summary

    A critical buffer overflow vulnerability (CVE-2026-34875) affecting public key export for FFDH keys in Mbed TLS and TF-PSA-Crypto is reported, with no evidence of exploitation, patches, or PoC provided.

    0000049
    163 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34875 - Mbed TLS FFDH Key Export Buffer Overflow Intel Report: https://ift.tt/Ox26Aew

    Post summary

    An alert announces CVE‑2026‑34875, a buffer‑overflow vulnerability in Mbed TLS FFDH Key Export, and provides an Intel report link for further details.

    0000052
    281 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptrustedfirmwarembed_tls---
Apptrustedfirmwaretf-psa-crypto---

Explore more