Description
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
Published: 2026-09-14
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Limited configuration flaw in TLS 1.3 client
Action: Patch
AI Analysis

Impact

The vulnerability exists in the Mbed TLS 3.6.x series before 3.6.7 and the 4.1.x series before 4.1.2. When a TLS 1.3 client uses these library versions, it accepts a HelloRetryRequest that contains an elliptic‑curve group not advertised in the original ClientHello. As a result, the client may negotiate a key‑exchange group it did not declare support for. The impact is confined to potential handshake failures or undesirable key‑exchange behavior, and there is no evidence of data exposure, code execution or other severe consequences (CWE‑669).

Affected Systems

TrustedFirmware’s Mbed TLS library in its 3.6.x releases prior to 3.6.7 and 4.1.x releases prior to 4.1.2 is affected. Any system that incorporates these library versions and initiates TLS 1.3 handshakes with a server capable of issuing unsuitable HelloRetryRequest messages may experience this flaw.

Risk and Exploitability

Attackers could trigger the flaw by acting as a TLS 1.3 server that issues a HelloRetryRequest with an unadvertised group. When such a request reaches an affected client, the client will accept it, potentially leading to a failed handshake or the use of an unintended cryptographic group. The CVSS score of 3.7 reflects a low severity, the EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 16:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade TrustedFirmware’s Mbed TLS to version 3.6.7 or later, or to 4.1.2 or later, which incorporates the fix that rejects unadvertised groups in HelloRetryRequest messages.
  • Replace all devices and software that embed vulnerable Mbed TLS versions with the patched releases, ensuring that every deployment now uses a fixed library version.
  • Implement monitoring of TLS handshakes on the network to detect anomalous HelloRetryRequest messages, which can help confirm that unpatched or misconfigured clients are no longer present.

Generated by OpenCVE AI on September 15, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Mbed TLS Vulnerability Allowing Unadvertised Group During TLS 1.3 HelloRetryRequest

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Mbed TLS TLS 1.3 Client Accepts HelloRetryRequest with Unadvertised Group

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Mbed TLS TLS 1.3 Client Accepts HelloRetryRequest with Unadvertised Group

Mon, 14 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Trustedfirmware
Trustedfirmware mbed Tls
Vendors & Products Trustedfirmware
Trustedfirmware mbed Tls

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
Weaknesses CWE-669
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Trustedfirmware Mbed Tls
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:00:15.430Z

Reserved: 2026-02-06T00:00:00.000Z

Link: CVE-2026-25832

cve-icon Vulnrichment

Updated: 2026-09-14T15:59:53.268Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T07:17:16.490

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-25832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:15:15Z

Weaknesses
  • CWE-669

    Incorrect Resource Transfer Between Spheres