PT-2026-29126 · Botan · Botan
Harutokimura
·
Publicado
2026-03-30
·
Atualizado
2026-04-20
·
CVE-2026-32884
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Botan versions prior to 3.11.0
Description
Botan is a C++ cryptography library. When processing X.509 certificate paths with DNS name constraints, a case-sensitive comparison of the Common Name (CN) allowed a certificate to bypass restrictions. Specifically, if an end-entity certificate lacked Subject Alternative Names, Botan incorrectly checked the CN against DNS name constraints, failing to account for mixed-case CNs. This allowed a certificate with a mixed-case CN, like
Sub.EVIL.COM, to bypass an excludedSubtrees constraint for evil.com. This behavior violates RFC 5280 standards.Recommendations
Update to version 3.11.0 or later.
Exploit
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Botan