CVE-2026-34580
published 2026-04-07CVE-2026-34580: Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.25%
16.4th percentile
Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the cert it found and the cert it was passed were actually the same certificate. In 3.11.0 an extension of path validation logic was made which assumed that certificate_known only returned true if the certificates were in fact identical. The impact is that if an end entity certificate is presented, and its DN (and subject key identifier, if set) match that of any trusted root, the end entity certificate is accepted immediately as if it itself were a trusted root. , This vulnerability is fixed in 3.11.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| botan_project | botan | — | — |
| debian | botan3 | — | — |
| randombit | botan | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Botan: Botan: Certificate validation bypass due to incorrect certificate matching
vendor_redhat·2026-04-07·CVSS 9.3
CVE-2026-34580 [CRITICAL] CWE-295 Botan: Botan: Certificate validation bypass due to incorrect certificate matching
Botan: Botan: Certificate validation bypass due to incorrect certificate matching
Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the cert it found and the cert it was passed were actually the same certificate. In 3.11.0 an extension of path validation logic was made which assumed that certificate_known only returned true if the certificates were in fact identical. The impact is that if an end entity certificate is presented, and its DN (and subject key identifier, if set) match that of any trusted root, the end entity certificate is accepted immediately as if it itse
Debian
CVE-2026-34580: botan3 - Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::...
vendor_debian·2026·CVSS 9.3
CVE-2026-34580 [CRITICAL] CVE-2026-34580: botan3 - Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::...
Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the cert it found and the cert it was passed were actually the same certificate. In 3.11.0 an extension of path validation logic was made which assumed that certificate_known only returned true if the certificates were in fact identical. The impact is that if an end entity certificate is presented, and its DN (and subject key identifier, if set) match that of any trusted root, the end entity certificate is accepted immediately as if it itself were a trusted root. , This vulnerability is fixed in 3.11.1.
Scope: local
forky
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34580 botan3: Botan: Certificate validation bypass due to incorrect certificate matching [epel-all]
bugzilla·2026-04-08·CVSS 9.3
CVE-2026-34580 [CRITICAL] CVE-2026-34580 botan3: Botan: Certificate validation bypass due to incorrect certificate matching [epel-all]
CVE-2026-34580 botan3: Botan: Certificate validation bypass due to incorrect certificate matching [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34580 botan2: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-42]
bugzilla·2026-04-08·CVSS 9.3
CVE-2026-34580 [CRITICAL] CVE-2026-34580 botan2: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-42]
CVE-2026-34580 botan2: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34580 botan2: Botan: Certificate validation bypass due to incorrect certificate matching [epel-all]
bugzilla·2026-04-08·CVSS 9.3
CVE-2026-34580 [CRITICAL] CVE-2026-34580 botan2: Botan: Certificate validation bypass due to incorrect certificate matching [epel-all]
CVE-2026-34580 botan2: Botan: Certificate validation bypass due to incorrect certificate matching [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34580 botan2: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-43]
bugzilla·2026-04-08·CVSS 9.3
CVE-2026-34580 [CRITICAL] CVE-2026-34580 botan2: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-43]
CVE-2026-34580 botan2: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34580 botan: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-43]
bugzilla·2026-04-08·CVSS 9.3
CVE-2026-34580 [CRITICAL] CVE-2026-34580 botan: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-43]
CVE-2026-34580 botan: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34580 botan: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-42]
bugzilla·2026-04-08·CVSS 9.3
CVE-2026-34580 [CRITICAL] CVE-2026-34580 botan: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-42]
CVE-2026-34580 botan: Botan: Certificate validation bypass due to incorrect certificate matching [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34580 Botan: Botan: Certificate validation bypass due to incorrect certificate matching
bugzilla·2026-04-07·CVSS 9.3
CVE-2026-34580 [CRITICAL] CVE-2026-34580 Botan: Botan: Certificate validation bypass due to incorrect certificate matching
CVE-2026-34580 Botan: Botan: Certificate validation bypass due to incorrect certificate matching
Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the cert it found and the cert it was passed were actually the same certificate. In 3.11.0 an extension of path validation logic was made which assumed that certificate_known only returned true if the certificates were in fact identical. The impact is that if an end entity certificate is presented, and its DN (and subject key identifier, if set) match that of any trusted root, the end entity certificate is accepted immediatel
Wiz
CVE-2026-34582 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-34582 [HIGH] CVE-2026-34582 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34582 :
Botan vulnerability analysis and mitigation
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Source : NVD
## 8.7
Score
Published April 7, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Botan
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploi
Wiz
CVE-2026-34580 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-34580 [HIGH] CVE-2026-34580 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34580 :
Botan vulnerability analysis and mitigation
Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the cert it found and the cert it was passed were actually the same certificate. In 3.11.0 an extension of path validation logic was made which assumed that certificate_known only returned true if the certificates were in fact identical. The impact is that if an end entity certificate is presented, and its DN (and subject key identifier, if set) match that of any trusted root, the end entity certificate is accepted immediately as if it itself were a trusted
2026-04-07
Published