CVE-2026-73064
LOW2.9CVSS v3
—CVSS v2
—
EPSS (exploit probability)
CWE-394CWE
Description
In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.
CVSS v3 vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.