Overview
What is CVE-2025-27809?
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
Vulnerability intelligence
CVE-2025-27809 and is rated Medium severity with a CVSS score of 5.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.