Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34582

Опубликовано: 07 апр. 2026
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.

A flaw was found in Botan, a C++ cryptography library. The TLS 1.3 implementation in Botan allows application data to be processed before the TLS handshake is fully completed. A remote attacker can exploit this by omitting critical client authentication messages, such as the Certificate, CertificateVerify, and Finished messages, and instead sending application data. This vulnerability enables a client to bypass server-enforced client authentication, potentially leading to unauthorized access.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rust-sequoia-sqWill not fix
Red Hat Enterprise Linux 10rust-sequoia-sqvWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-166
https://bugzilla.redhat.com/show_bug.cgi?id=2456285botan: Botan: Client authentication bypass in TLS 1.3 implementation

EPSS

Процентиль: 14%
0.00233
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
4 месяца назад

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.

CVSS3: 9.1
nvd
4 месяца назад

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.

CVSS3: 9.1
debian
4 месяца назад

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS ...

suse-cvrf
4 месяца назад

Security update for Botan

EPSS

Процентиль: 14%
0.00233
Низкий

9.1 Critical

CVSS3

Уязвимость CVE-2026-34582