CVE-2026-32877
published 2026-03-30CVE-2026-32877: Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value…
PriorityP345high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
EPSS
0.28%
20.1th percentile
Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C3) failed to check that the encoded value was of the expected length prior to comparison. An invalid ciphertext can cause a heap over-read of up to 31 bytes, resulting in a crash or potentially other undefined behavior. This issue has been patched in version 3.11.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| botan_project | botan | >= 2.3.0 < 3.11.0 | 3.11.0 |
| debian | botan | < botan3 3.11.0+dfsg-2 (sid) | botan3 3.11.0+dfsg-2 (sid) |
| debian | botan3 | < botan3 3.11.0+dfsg-2 (sid) | botan3 3.11.0+dfsg-2 (sid) |
| randombit | botan | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
osv8.2HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Botan: Botan: Denial of Service via heap over-read during SM2 decryption
vendor_redhat·2026-03-30·CVSS 8.2
CVE-2026-32877 [HIGH] CWE-1284 Botan: Botan: Denial of Service via heap over-read during SM2 decryption
Botan: Botan: Denial of Service via heap over-read during SM2 decryption
Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C3) failed to check that the encoded value was of the expected length prior to comparison. An invalid ciphertext can cause a heap over-read of up to 31 bytes, resulting in a crash or potentially other undefined behavior. This issue has been patched in version 3.11.0.
A flaw was found in Botan, a C++ cryptography library. During SM2 decryption, the library failed to validate the length of the authentication code value (C3) before comparison. A remote attacker could exploit this by providing a specially crafted invalid ciphertext, leading to a heap over-read of u
Debian
CVE-2026-32877: botan - Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0...
vendor_debian·2026·CVSS 8.2
CVE-2026-32877 [HIGH] CVE-2026-32877: botan - Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0...
Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C3) failed to check that the encoded value was of the expected length prior to comparison. An invalid ciphertext can cause a heap over-read of up to 31 bytes, resulting in a crash or potentially other undefined behavior. This issue has been patched in version 3.11.0.
Scope: local
bookworm: open
bullseye: open
trixie: open
VulDB
randombit botan up to 3.10.x out-of-bounds (GHSA-7jj6-4r42-w9h6 / Nessus ID 310592)
vuldb·2026-04-29·CVSS 8.2
CVE-2026-32877 [HIGH] randombit botan up to 3.10.x out-of-bounds (GHSA-7jj6-4r42-w9h6 / Nessus ID 310592)
A vulnerability described as critical has been identified in randombit botan up to 3.10.x. Impacted is an unknown function. The manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-32877. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
OSV
CVE-2026-32877: Botan is a C++ cryptography library
osv·2026-03-30·CVSS 8.2
CVE-2026-32877 [HIGH] CVE-2026-32877: Botan is a C++ cryptography library
Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C3) failed to check that the encoded value was of the expected length prior to comparison. An invalid ciphertext can cause a heap over-read of up to 31 bytes, resulting in a crash or potentially other undefined behavior. This issue has been patched in version 3.11.0.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-32877 botan2: Botan: Denial of Service via heap over-read during SM2 decryption [fedora-43]
bugzilla·2026-04-01·CVSS 8.2
CVE-2026-32877 [HIGH] CVE-2026-32877 botan2: Botan: Denial of Service via heap over-read during SM2 decryption [fedora-43]
CVE-2026-32877 botan2: Botan: Denial of Service via heap over-read during SM2 decryption [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
botan2 is EOL.
Bugzilla
CVE-2026-32877 botan3: Botan: Denial of Service via heap over-read during SM2 decryption [epel-all]
bugzilla·2026-04-01·CVSS 8.2
CVE-2026-32877 [HIGH] CVE-2026-32877 botan3: Botan: Denial of Service via heap over-read during SM2 decryption [epel-all]
CVE-2026-32877 botan3: Botan: Denial of Service via heap over-read during SM2 decryption [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-a0842eadb1 (botan3-3.9.0-3.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a0842eadb1
---
FEDORA-EPEL-2026-a0842eadb1 has been pushed to the Fedora EPEL 10.3 testing repository.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a0842eadb1
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more informati
Bugzilla
CVE-2026-32877 botan2: Botan: Denial of Service via heap over-read during SM2 decryption [epel-all]
bugzilla·2026-04-01·CVSS 8.2
CVE-2026-32877 [HIGH] CVE-2026-32877 botan2: Botan: Denial of Service via heap over-read during SM2 decryption [epel-all]
CVE-2026-32877 botan2: Botan: Denial of Service via heap over-read during SM2 decryption [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
botan 2 is EOL.
Bugzilla
CVE-2026-32877 botan: Botan: Denial of Service via heap over-read during SM2 decryption [fedora-42]
bugzilla·2026-04-01·CVSS 8.2
CVE-2026-32877 [HIGH] CVE-2026-32877 botan: Botan: Denial of Service via heap over-read during SM2 decryption [fedora-42]
CVE-2026-32877 botan: Botan: Denial of Service via heap over-read during SM2 decryption [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained versio
Bugzilla
CVE-2026-32877 botan2: Botan: Denial of Service via heap over-read during SM2 decryption [fedora-42]
bugzilla·2026-04-01·CVSS 8.2
CVE-2026-32877 [HIGH] CVE-2026-32877 botan2: Botan: Denial of Service via heap over-read during SM2 decryption [fedora-42]
CVE-2026-32877 botan2: Botan: Denial of Service via heap over-read during SM2 decryption [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
botan2 is EOL.
Wiz
CVE-2026-34582 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-34582 [HIGH] CVE-2026-34582 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34582 :
Botan vulnerability analysis and mitigation
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Source : NVD
## 8.7
Score
Published April 7, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Botan
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploi
Wiz
CVE-2026-32884 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-32884 [MEDIUM] CVE-2026-32884 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32884 :
Botan vulnerability analysis and mitigation
Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name constraints which restrict the set of allowable DNS names, if no subject alternative name is defined in the end-entity certificate Botan would check that the CN was allowed by the DNS name constraints, even though this check is technically not required by RFC 5280. However this check failed to account for the possibility of a mixed-case CN. Thus a certificate with CN=Sub.EVIL.COM and no subject alternative name would bypasses an excludedSubtrees constraint for evil.com because the comparison is case-sensitive. This issue has been patched in version 3.11.0.
Source : NVD
## 5.9
Score
Published March 30,
Wiz
CVE-2026-32877 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-32877 [MEDIUM] CVE-2026-32877 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32877 :
Botan vulnerability analysis and mitigation
Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C3) failed to check that the encoded value was of the expected length prior to comparison. An invalid ciphertext can cause a heap over-read of up to 31 bytes, resulting in a crash or potentially other undefined behavior. This issue has been patched in version 3.11.0.
Source : NVD
## 8.2
Score
Published March 30, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
Botan
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.7
Exploitation Probability (EPS
Wiz
CVE-2026-34580 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-34580 [HIGH] CVE-2026-34580 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34580 :
Botan vulnerability analysis and mitigation
Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the cert it found and the cert it was passed were actually the same certificate. In 3.11.0 an extension of path validation logic was made which assumed that certificate_known only returned true if the certificates were in fact identical. The impact is that if an end entity certificate is presented, and its DN (and subject key identifier, if set) match that of any trusted root, the end entity certificate is accepted immediately as if it itself were a trusted
Wiz
CVE-2026-32883 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-32883 [MEDIUM] CVE-2026-32883 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32883 :
Botan vulnerability analysis and mitigation
Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.
Source : NVD
## 5.9
Score
Published March 30, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Botan
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
botan3
rust-sequoia-sq
Sources
NVD
Debian 13, 14 Severity MEDIUM No Fix Added at: Apr
2026-03-30
Published