CVE-2026-34582

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*

History

30 Jun 2026, 03:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/security/cve/CVE-2026-34582 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2456285 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34582.json -
CWE CWE-166

17 Jun 2026, 10:39

Type Values Removed Values Added
References () https://github.com/randombit/botan/security/advisories/GHSA-pxcj-9ppx-g86g - Vendor Advisory, Mitigation () https://github.com/randombit/botan/security/advisories/GHSA-pxcj-9ppx-g86g - Mitigation, Vendor Advisory

17 Apr 2026, 20:31

Type Values Removed Values Added
References () https://github.com/randombit/botan/security/advisories/GHSA-pxcj-9ppx-g86g - () https://github.com/randombit/botan/security/advisories/GHSA-pxcj-9ppx-g86g - Vendor Advisory, Mitigation
First Time Botan Project botan
Botan Project
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CPE cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*

07 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 22:16

Updated : 2026-07-15 02:20


NVD link : CVE-2026-34582

Mitre link : CVE-2026-34582

CVE.ORG link : CVE-2026-34582


JSON object : View

Products Affected

botan_project

  • botan
CWE
CWE-841

Improper Enforcement of Behavioral Workflow

CWE-166

Improper Handling of Missing Special Element