CVE-2026-34582
published 2026-04-07CVE-2026-34582: Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished…
PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.23%
14.4th percentile
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| botan_project | botan | 3.0.0 – 3.11.0 | — |
| debian | botan | < botan3 3.11.0+dfsg-2 (sid) | botan3 3.11.0+dfsg-2 (sid) |
| debian | botan3 | < botan3 3.11.0+dfsg-2 (sid) | botan3 3.11.0+dfsg-2 (sid) |
| randombit | botan | < 3.11.1 | 3.11.1 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
botan: Botan: Client authentication bypass in TLS 1.3 implementation
vendor_redhat·2026-04-07·CVSS 8.7
CVE-2026-34582 [HIGH] CWE-166 botan: Botan: Client authentication bypass in TLS 1.3 implementation
botan: Botan: Client authentication bypass in TLS 1.3 implementation
A flaw was found in Botan, a C++ cryptography library. The TLS 1.3 implementation in Botan allows application data to be processed before the TLS handshake is fully completed. A remote attacker can exploit this by omitting critical client authentication messages, such as the Certificate, CertificateVerify, and Finished messages, and instead sending application data. This vulnerability enables a client to bypass server-enforced client authentication, potentially leading to unauthorized access.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base
Debian
CVE-2026-34582: botan - Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implem...
vendor_debian·2026·CVSS 8.7
CVE-2026-34582 [HIGH] CVE-2026-34582: botan - Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implem...
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Scope: local
bookworm: open
bullseye: open
trixie: open
OSV
CVE-2026-34582: Botan is a C++ cryptography library
osv·2026-04-07·CVSS 8.7
CVE-2026-34582 [HIGH] CVE-2026-34582: Botan is a C++ cryptography library
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34582 botan2: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-42]
bugzilla·2026-04-08·CVSS 8.7
CVE-2026-34582 [HIGH] CVE-2026-34582 botan2: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-42]
CVE-2026-34582 botan2: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34582 botan: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-43]
bugzilla·2026-04-08·CVSS 8.7
CVE-2026-34582 [HIGH] CVE-2026-34582 botan: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-43]
CVE-2026-34582 botan: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34582 botan2: Botan: Client authentication bypass in TLS 1.3 implementation [epel-all]
bugzilla·2026-04-08·CVSS 8.7
CVE-2026-34582 [HIGH] CVE-2026-34582 botan2: Botan: Client authentication bypass in TLS 1.3 implementation [epel-all]
CVE-2026-34582 botan2: Botan: Client authentication bypass in TLS 1.3 implementation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34582 botan3: Botan: Client authentication bypass in TLS 1.3 implementation [epel-all]
bugzilla·2026-04-08·CVSS 8.7
CVE-2026-34582 [HIGH] CVE-2026-34582 botan3: Botan: Client authentication bypass in TLS 1.3 implementation [epel-all]
CVE-2026-34582 botan3: Botan: Client authentication bypass in TLS 1.3 implementation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34582 botan2: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-43]
bugzilla·2026-04-08·CVSS 8.7
CVE-2026-34582 [HIGH] CVE-2026-34582 botan2: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-43]
CVE-2026-34582 botan2: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34582 botan: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-42]
bugzilla·2026-04-08·CVSS 8.7
CVE-2026-34582 [HIGH] CVE-2026-34582 botan: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-42]
CVE-2026-34582 botan: Botan: Client authentication bypass in TLS 1.3 implementation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34582 botan: Botan: Client authentication bypass in TLS 1.3 implementation
bugzilla·2026-04-07·CVSS 8.7
CVE-2026-34582 [HIGH] CVE-2026-34582 botan: Botan: Client authentication bypass in TLS 1.3 implementation
CVE-2026-34582 botan: Botan: Client authentication bypass in TLS 1.3 implementation
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Wiz
CVE-2026-34582 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-34582 [HIGH] CVE-2026-34582 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34582 :
Botan vulnerability analysis and mitigation
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Source : NVD
## 8.7
Score
Published April 7, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Botan
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploi
Wiz
CVE-2026-34580 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-34580 [HIGH] CVE-2026-34580 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34580 :
Botan vulnerability analysis and mitigation
Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the cert it found and the cert it was passed were actually the same certificate. In 3.11.0 an extension of path validation logic was made which assumed that certificate_known only returned true if the certificates were in fact identical. The impact is that if an end entity certificate is presented, and its DN (and subject key identifier, if set) match that of any trusted root, the end entity certificate is accepted immediately as if it itself were a trusted
2026-04-07
Published