Hello again,

Looking at the content of the issue, it is one of the two bugs in basicConstraints parsing covered by CVE-2026-49300, which we fixed in our July release.
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-x509-ca-bit-forgery-invalid-basicconstraints/

I can add you as an independent reporter to the credits list. Let me know how you'd like to be acknowledged.

-- 
Best regards,

Gilles Peskine

On 19/08/2026 10:15, Maximilian Radoy wrote:

Dear Gilles Peskine,

we are trying to get in contact with mbed-tls-security@lists.trustedfirmware.org for almost three months now regarding a security-relevant finding in mbedtls, but we do not get any response at all.

As you seem to be (according to github) actively involved in that project, we'd like to ask you whether there are any alternative ways to deliver our security report? Otherwise, we may post it as regular github issue.

Thank you in advance for your help!

Best regards,
Maximilian Radoy

--

Maximilian Radoy
Research Assistant
System Security Group
Paderborn University
Universität Paderborn
Fürstenallee 11
33102 Paderborn
Germany
Office F2.308
Telephone +49 5251 60-6724
E-Mail maximilian.radoy@uni-paderborn.de


Instagram Facebook LinkedIn YouTube