CVE-2026-34872 An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).

Information published.


CVE-2026-34871 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).

Information published.


CVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

Information published.


CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

Information published.


CVE-2026-43352 i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue

Information published.


CVE-2026-31717 ksmbd: validate owner of durable handle on reconnect

Information published.


CVE-2026-41673 xmldom: Denial of service via uncontrolled recursion in XML serialization

Information published.


CVE-2026-41675 xmldom: XML node injection through unvalidated processing instruction serialization

Information published.


CVE-2026-41674 xmldom: XML injection through unvalidated DocumentType serialization

Information published.


CVE-2026-41672 xmldom: XML node injection through unvalidated comment serialization

Information published.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

AbuseIPDB Contributor Badge