PT-2026-29125 · Botan · Botan

Harutokimura

·

Publicado

2026-03-30

·

Atualizado

2026-03-31

·

CVE-2026-32883

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Botan versions 3.0.0 through 3.10.9
Description Botan is a C++ cryptography library. During X509 path validation, versions prior to 3.11.0 did not verify the signature of Online Certificate Status Protocol (OCSP) responses, only checking for an appropriate status code. This could allow a man-in-the-middle (MitM) attack to bypass certificate revocation checks.
Recommendations Update to Botan version 3.11.0 or later.

Exploit

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32883
GHSA-9J2J-HQMC-HF5X

Produtos afetados

Botan