Multiple Vulnerabilities Found in Mbed TLS Affecting Key Security
First seen 18 Feb 2026, 12:23 UTC
•
•39
Export
Article Content
Browse articles
Two vulnerabilities have been identified in Mbed TLS that could allow attackers to extract sensitive cryptographic keys. CVE-2020-10941, published on March 24, 2020, enables attackers to obtain RSA private keys through cache measurement. CVE-2025-52496, published on July 4, 2025, presents a race condition that may allow AES key extraction or GCM forgery in multithreaded applications.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2020-03-24
CVE-2020-10941 published
2025-07-04
CVE-2025-52496 published
2026-02-18
Information published about both vulnerabilities