CVE-2026-73064 Overview
CVE-2026-73064 affects Mbed TLS versions 3.2.0 through 3.6.6 and 4.0.0 through 4.1.0. An attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. The flaw only impacts TLS 1.3 servers. The weakness maps to [CWE-394: Unexpected Status Code or Return Value], reflecting improper handling of a failed random number generator return path.
Critical Impact
Entropy source failure on a TLS 1.3 server allows an attacker to manipulate bytes at the start of the TLS stream, undermining integrity of the handshake.
Affected Products
- Mbed TLS 3.2.0 through 3.6.6
- Mbed TLS 4.0.0 through 4.1.0
- TLS 1.3 server deployments linking the above versions
Discovery Timeline
- 2026-09-24 - CVE CVE-2026-73064 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-73064
Vulnerability Analysis
The vulnerability resides in the TLS 1.3 server code path of Mbed TLS. When the configured entropy source fails, the random number generator returns an error that the TLS stack does not fully propagate. The result is that random material intended to protect the start of the TLS stream is replaced or omitted. An attacker positioned to trigger the entropy failure can then remove or inject bytes at the beginning of the stream, breaking TLS integrity guarantees for that session.
Exploitation requires the ability to induce an entropy source fault on the target server. The attack vector is local, and complexity is high because an attacker must coordinate the entropy failure with the handshake. Only confidentiality of integrity properties on the stream prefix is impacted; the issue does not grant remote code execution.
Root Cause
The root cause is improper handling of a failure return value from the entropy source during TLS 1.3 handshake processing. The server continues the handshake despite missing or corrupted randomness, violating the assumption that random bytes used to seed early stream state are unpredictable.
Attack Vector
An attacker with local influence over the entropy subsystem, such as a co-located workload able to exhaust or disable the entropy device, forces the random generator to fail. During a subsequent TLS 1.3 handshake, the attacker injects or removes bytes at the stream start. Successful manipulation requires precise timing against the failed entropy condition.
No verified proof-of-concept code is published. Technical details are available in the Mbed TLS Security Advisory 2026-07.
Detection Methods for CVE-2026-73064
Indicators of Compromise
- Entropy source errors or warnings in server logs correlated with TLS 1.3 handshake failures
- Unexpected TLS 1.3 handshake aborts or protocol errors at session start
- Repeated failures of the configured random number generator on hosts running vulnerable Mbed TLS versions
Detection Strategies
- Inventory binaries and containers for linked Mbed TLS versions 3.2.0 through 3.6.6 and 4.0.0 through 4.1.0
- Alert on logs reporting entropy or DRBG errors from Mbed TLS during active TLS sessions
- Monitor TLS 1.3 server telemetry for anomalous handshake truncation or malformed ClientHello processing
Monitoring Recommendations
- Instrument hosts to report entropy pool health metrics and surface sustained low-entropy conditions
- Centralize Mbed TLS error output into the SIEM for correlation with handshake failure spikes
- Track process-level anomalies on servers that terminate TLS 1.3 traffic
How to Mitigate CVE-2026-73064
Immediate Actions Required
- Identify all services and embedded devices linking Mbed TLS 3.2.0 through 3.6.6 or 4.0.0 through 4.1.0
- Upgrade to a fixed Mbed TLS release per the vendor advisory as soon as it is available for your branch
- Restrict local access on hosts terminating TLS 1.3 to reduce the ability of attackers to influence entropy sources
Patch Information
Refer to the Mbed TLS Security Advisory 2026-07 for fixed version information and backport guidance. Source code and release tags are available in the GitHub Mbed TLS Repository.
Workarounds
- Ensure the entropy source is hardened and monitored so failure conditions cannot be reliably induced by local actors
- Where feasible, disable TLS 1.3 on servers that cannot be patched promptly and fall back to TLS 1.2
- Enforce strict least-privilege controls on co-tenant workloads that share entropy hardware with TLS 1.3 servers
# Configuration example
# Verify linked Mbed TLS version on a Linux host
ldd /path/to/your/tls-server | grep -i mbedtls
strings /path/to/libmbedtls.so* | grep -i "mbed TLS"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.