TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group. (CVE-2026-25832) Possible buffer overflow in mbedtls_ecdh_calc_secret(). (CVE-2026-35336) X.509 CA bit forgery via invalid basicConstraints extension. (CVE-2026-49300) Use-after-free in mbedtls_pkcs7_free() when reusing a PKCS7 context. (CVE-2026-50579) Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake. (CVE-2026-50580) Extended master secret calculation failure ignored. (CVE-2026-50581) A 1-byte buffer overread when parsing a malformed ECC public key in the PK module. (CVE-2026-50583) ChaCha20 counter overflow can reuse keystream. (CVE-2026-50584) Incomplete context reset in mbedtls_ssl_session_reset(). (CVE-2026-50585) A potential information disclosure in TLS 1.2 servers using session tickets. If the session ticket write callback failed without setting the lifetime output parameter, Mbed TLS could send 4 bytes of uninitialized stack memory to the peer in the NewSessionTicket message. (CVE-2026-50586) Timing side-channel in RSA PKCS#1 v1.5 decryption. (CVE-2026-50587) Out-of-bounds read in TLS 1.2 EC J-PAKE ServerKeyExchange parsing. (CVE-2026-50588) Ignored TLS 1.3 resumption secret derivation error. (CVE-2026-50640) Heap corruption with early renegotiation after corrupted record in DTLS. (CVE-2026-50713) Side channel leak in ECC optimized modp. (CVE-2026-54435) Signature algorithm restrictions not enforced on certificate chain. (CVE-2026-54441) A random generator fault can compromise TLS data integrity. (CVE-2026-73064)