Loading
Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
Use CWE-908, Arm vendor hub and Mbed Tls product page to widen CVE-2025-27810 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34877, CVE-2026-34875 and CVE-2026-34873 for nearby disclosures in the same product family.