{"id":"CVE-2026-25832","title":"In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.","summary":"In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-669"],"vendor":"TrustedFirmware","product":"Mbed TLS","affected":["mbed_tls >= 3.5.0 < 3.6.7","mbed_tls >= 4.0.0 < 4.1.2"],"published":"2026-09-14","updated":"2026-09-22","sourceUpdated":"2026-09-22T19:56:19.073","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-25832","references":[{"url":"https://mbed-tls.readthedocs.io/en/latest/security-advisories/","label":"cve@mitre.org"},{"url":"https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls13-hrr-unadvertised-group/","label":"cve@mitre.org"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25832.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-25832"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-25832"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00218,"epssPercentile":0.12506,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T15:59:33.992126Z"},"ingestedAt":"2026-09-14T15:23:07.465Z","slug":"CVE-2026-25832","body":"## Overview\n\nIn Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25832.json)","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}