CVE-2026-34873
Description
A flaw was found in Mbed TLS. This vulnerability allows a remote attacker to impersonate a client during the resumption of a TLS 1.3 session. This could lead to unauthorized access or other security breaches by allowing the attacker to act as a legitimate client.
Statement
This Critical flaw in Mbed TLS allows a remote attacker to impersonate a client during TLS 1.3 session resumption, potentially leading to unauthorized access. Red Hat products utilizing Mbed TLS for client-side TLS 1.3 session resumption are affected if this feature is enabled.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Bypass Protection Mechanism; Gain Privileges or Assume Identity
This weakness can allow an attacker to access resources which are not otherwise accessible without proper authentication.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.