Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtlspemreadbuffer and two mbedtlspk_parse functions, via untrusted PEM input.
{ "versions": [ { "introduced": "0" }, { "fixed": "3.6.4" } ] }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-52497.json"