Overview
What is CVE-2026-25834?
Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
Vulnerability intelligence
CVE-2026-25834 and is rated Medium severity with a CVSS score of 6.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.