Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-34874

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.0%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-34874
  • Arm » Mbed Tls » Version: 3.5.0
    cpe:2.3:a:arm:mbed_tls:3.5.0
  • Arm » Mbed Tls » Version: 3.5.1
    cpe:2.3:a:arm:mbed_tls:3.5.1
  • Arm » Mbed Tls » Version: 3.5.2
    cpe:2.3:a:arm:mbed_tls:3.5.2
  • Arm » Mbed Tls » Version: 3.6.0
    cpe:2.3:a:arm:mbed_tls:3.6.0
  • Arm » Mbed Tls » Version: 3.6.1
    cpe:2.3:a:arm:mbed_tls:3.6.1
  • Arm » Mbed Tls » Version: 3.6.2
    cpe:2.3:a:arm:mbed_tls:3.6.2
  • Arm » Mbed Tls » Version: 3.6.3
    cpe:2.3:a:arm:mbed_tls:3.6.3
  • Arm » Mbed Tls » Version: 3.6.4
    cpe:2.3:a:arm:mbed_tls:3.6.4
  • Arm » Mbed Tls » Version: 3.6.5
    cpe:2.3:a:arm:mbed_tls:3.6.5
  • Arm » Mbed Tls » Version: 4.0.0
    cpe:2.3:a:arm:mbed_tls:4.0.0


Contact Us

Shodan ® - All rights reserved