Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-32883

Опубликовано: 30 мар. 2026
Источник: debian
EPSS Низкий

Описание

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
botan3fixed3.11.0+dfsg-1experimentalpackage
botan3fixed3.11.0+dfsg-2package
botannot-affectedpackage

Примечания

  • https://github.com/randombit/botan/security/advisories/GHSA-9j2j-hqmc-hf5x

  • https://github.com/randombit/botan/commit/acbffadcede18b36eea42beae57e6cae4b4da4a0 (3.11.0)

EPSS

Процентиль: 5%
0.00154
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.

CVSS3: 6.8
redhat
4 месяца назад

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.

CVSS3: 5.9
nvd
4 месяца назад

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.

CVSS3: 5.9
fstec
4 месяца назад

Уязвимость компонента X509 Path Validation Handler криптографической библиотеки C++ Botan, позволяющая нарушителю подделать ответы OCSP

EPSS

Процентиль: 5%
0.00154
Низкий