PT-2026-31028 · Botan · Botan
Ben Smyth
·
Published
2026-04-07
·
Updated
2026-04-14
·
CVE-2026-34582
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Botan versions prior to 3.11.1
Description
The TLS 1.3 implementation in Botan allowed processing of ApplicationData records before the Finished message was received. This could allow a client to bypass server-enforced client authentication via certificates by omitting the Certificate, CertificateVerify, and Finished messages and instead sending application data records.
Recommendations
Update to version 3.11.1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Botan