Title: September 2026 Mbed TLS Vulnerabilities in StarWind Products

Note: StarWind will continue to update this vulnerability as new information becomes available.

Vulnerability ID: SW-20260921-0001

Version: 1.0

Date: 2026-09-21

Status: Interim

CVEs: CVE-2026-34873, CVE-2026-34872, CVE-2026-34875, CVE-2026-25835, CVE-2026-34874

Summary

It was discovered that Mbed TLS incorrectly handled several cryptographic and protocol operations. CVE-2026-34873 allows client impersonation while resuming a TLS 1.3 session. CVE-2026-34872 allows a remote peer to force a Diffie-Hellman shared secret into a small, predictable set of values due to a lack of contributory behavior checking. CVE-2026-25835 causes seed values to be misused in the library’s Pseudo-Random Number Generator. CVE-2026-34874 causes a NULL pointer dereference during distinguished name parsing. CVE-2026-34875 is a buffer overflow in public key export for FFDH keys.

Impact

An attacker could possibly use CVE-2026-34873 or CVE-2026-34872 to impersonate a legitimate TLS peer or predict session key material without authentication, compromising the confidentiality and integrity of the connection. CVE-2026-34875 could allow arbitrary code execution in the context of the process performing the key export. CVE-2026-25835 could allow an attacker with local access to predict PRNG output. CVE-2026-34874 could cause a denial of service via a crash during certificate parsing.

Vulnerability Scoring

CVE CVSS 3.x Score Vector CVSS 4.0 Score Vector
CVE-2026-34873 9.1 Critical CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N N/A N/A
CVE-2026-34872 9.1 Critical CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N N/A N/A
CVE-2026-34875 9.8 Critical CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H N/A N/A
CVE-2026-25835 7.7 High CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N 8.5 High CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVE-2026-34874 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H N/A N/A

 

References

Resource Hyperlink
Mbed TLS Security Advisories https://mbed-tls.readthedocs.io/en/latest/security-advisories/
CVE.org – CVE-2026-34873 https://cve.org/CVERecord?id=CVE-2026-34873
Debian Security Tracker – mbedtls https://security-tracker.debian.org/tracker/source-package/mbedtls
NIST NVD – CVE-2026-34873 https://nvd.nist.gov/vuln/detail/CVE-2026-34873
NIST NVD – CVE-2026-34872 https://nvd.nist.gov/vuln/detail/CVE-2026-34872
NIST NVD – CVE-2026-34875 https://nvd.nist.gov/vuln/detail/CVE-2026-34875
NIST NVD – CVE-2026-25835 https://nvd.nist.gov/vuln/detail/CVE-2026-25835
NIST NVD – CVE-2026-34874 https://nvd.nist.gov/vuln/detail/CVE-2026-34874

 

Affected Products:

StarWind VSAN CVM Version 20260918 Version V8 (build 20104)

Software Versions and Fixes

None

Workaround

None

This section will be updated as patches are released

Obtaining Software Fixes

Software updates will be available in StarWind release notes – https://www.starwindsoftware.com/release-notes-build. To update the software, perform the steps described at the following link – https://knowledgebase.starwindsoftware.com/guidance/upgrading-from-any-starwind-version-to-any-starwind-version/ or contact support to perform an update. You can submit a support request using the following link https://www.starwindsoftware.com/support-form or contact Support directly via email support@starwind.com or via phone +1 617 829 4499.

Status of Notice

Interim

StarWind will continue to update information regarding this vulnerability as new details become available. This vulnerability article should be considered as the single source of current, up-to-date, authorized and accurate information posted by StarWind Software.

Revision History

Revision # Date Comments
1.0 2026-09-21 Initial Public Release