Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32883

Опубликовано: 30 мар. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.

A flaw was found in Botan. A remote attacker could exploit a vulnerability in the X509 path validation process where the signature of Online Certificate Status Protocol (OCSP) responses was not verified. This omission allows an attacker to provide forged OCSP responses, potentially leading to the acceptance of revoked certificates and compromising the integrity of the certificate validation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rust-sequoia-sqFix deferred
Red Hat Enterprise Linux 10rust-sequoia-sqvFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2453204Botan: Botan: Compromised certificate validation integrity via unverified OCSP response signatures

EPSS

Процентиль: 5%
0.00154
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.

CVSS3: 5.9
nvd
4 месяца назад

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.

CVSS3: 5.9
debian
4 месяца назад

Botan is a C++ cryptography library. From version 3.0.0 to before vers ...

CVSS3: 5.9
fstec
4 месяца назад

Уязвимость компонента X509 Path Validation Handler криптографической библиотеки C++ Botan, позволяющая нарушителю подделать ответы OCSP

EPSS

Процентиль: 5%
0.00154
Низкий

6.8 Medium

CVSS3

Уязвимость CVE-2026-32883