CVE-2025-52497 | mbed TLS up to 3.6.3 PEM mbedtls_pem_read_buffer off-by-one (EUVD-2025-20082 / Nessus ID 276316)
A vulnerability described as problematic has been identified in mbed TLS up to 3.6.3. The impacted element is the function mbedtls_pem_read_buffer of the component PEM Handler. The manipulation results in off-by-one.
This vulnerability is known as CVE-2025-52497. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.