PT-2026-29126 · Botan · Botan

Harutokimura

·

Publicado

2026-03-30

·

Atualizado

2026-04-20

·

CVE-2026-32884

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Botan versions prior to 3.11.0
Description Botan is a C++ cryptography library. When processing X.509 certificate paths with DNS name constraints, a case-sensitive comparison of the Common Name (CN) allowed a certificate to bypass restrictions. Specifically, if an end-entity certificate lacked Subject Alternative Names, Botan incorrectly checked the CN against DNS name constraints, failing to account for mixed-case CNs. This allowed a certificate with a mixed-case CN, like Sub.EVIL.COM, to bypass an excludedSubtrees constraint for evil.com. This behavior violates RFC 5280 standards.
Recommendations Update to version 3.11.0 or later.

Exploit

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32884
GHSA-7C3G-7763-GGJ5
OPENSUSE-SU-2026:20566-1

Produtos afetados

Botan