---
id: CVE-2026-73064
title: >-
  In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can
  cause an entropy source to fail can remove or inject bytes into the start of
  the TLS stream
summary: >-
  In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can
  cause an entropy source to fail can remove or inject bytes into the start of
  the TLS stream. This only affects TLS 1.3 servers.
severity: low
cvss: 2.9
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-394
vendor: trustedfirmware
product: Mbed TLS
affected:
  - mbed_tls >= 3.2.0 < 3.6.7
  - mbed_tls >= 4.0.0 < 4.1.1
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:04:40.340'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73064'
references:
  - url: 'https://github.com/Mbed-TLS/mbedtls'
    label: cve@mitre.org
  - url: >-
      https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-random-generator-fault-tls-integrity/
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T18:00:13.513498Z'
ingestedAt: '2026-09-24T15:45:56.644Z'
---

## Overview

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
