cbcvebase.
CVE-2025-27809
published 2025-03-25

CVE-2025-27809: Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client…

PriorityP428medium5.4CVSS 3.1
AVNACHPRNUINSCCLILAN
EPSS
0.18%
8.2th percentile
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

Affected

9 ranges
VendorProductVersion rangeFixed in
armmbed_tls< 2.28.102.28.10
debianmbedtls< mbedtls 3.6.3-1 (forky)mbedtls 3.6.3-1 (forky)
mbedmbedtls< 2.28.102.28.10
mbedmbedtls>= 0 < 3.6.3-13.6.3-1
mbedmbedtls>= 0 < 3.6.3-13.6.3-1
mbedmbedtls>= 3.0.0 < 3.6.33.6.3
msrcazl3_qemu_8.2.0-16_on_azure_linux_3.0
msrccbl2_qemu_6.2.0-24_on_cbl_mariner_2.0
trustedfirmwarembed_tls>= 3.0.0 < 3.6.33.6.3

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_msrc5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.