Skip to main content
Echelon
Graph
Product
Directory
Enterprise
Compliance
Pulse
Exposures
AI Analyst
Compare
Docs
Login
Start Free
Pulse
›
Vendor Advisories
›
Microsoft Security Response Center (MSRC)
›
CVE-2025-27809
CVE-2025-27809
Medium
CVSS
5.4
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
Vendor
Microsoft Security Response Center (MSRC)
Published
July 11, 2026
Last Modified
—
🔗 CVE IDs covered (1)
CVE-2025-27809 →