Executive brief
Mbed TLS is a widely used cryptographic library that helps secure communications for embedded devices and applications. A vulnerability in certain versions allows a malicious or misconfigured server to force a client to use weaker security settings than intended during a TLS 1.2 connection. This could lead to a bypass of corporate security policies, potentially allowing the use of outdated or insecure encryption methods that the client was configured to reject.
Technical details
An algorithm downgrade vulnerability exists in Mbed TLS 1.2 client implementations. When a server ignores the signature algorithms extension provided in the Client Hello, the client fails to validate the server's choice against its local security policy configured via mbedtls_ssl_conf_sig_algs(). Instead, the client accepts any signature algorithm supported at compile-time, even if it was explicitly excluded from the runtime configuration. This allows a network-positioned attacker (acting as a server) to bypass intended cryptographic restrictions. The issue is resolved in Mbed TLS 3.6.6 and 4.1.0.
Affected products
- TrustedFirmware Mbed TLS 3.3.0 to 3.6.5, 4.0.0
Timeline
- 2026-03-31: advisory: Vendor advisory published by Mbed TLS team
- 2026-04-01: disclosed: CVE published to NVD