Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
ECHO-516b-9033-dc39
See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-516b-9033-dc39.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-516b-9033-dc39
Upstream
CVE-2025-66442
Withdrawn
2026-05-28T11:30:04Z
Published
2026-05-27T09:20:26Z
Modified
2026-09-15T03:33:42Z
Summary
Compiler-induced timing side channel only with Clang select-optimize. Debian builds with GCC. https://security-tracker.debian.org/tracker/CVE-2025-66442
Details
References
https://advisory.echohq.com/cve/CVE-2025-66442
Affected packages
Echo
/
mbedtls
Package
Name
mbedtls
Purl
pkg:deb/echo/mbedtls
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.6.6-0.1+e1
Database specific
source
"https://advisory.echohq.com/osv/ECHO-516b-9033-dc39.json"
ECHO-516b-9033-dc39 - OSV