Critical severity9.1NVD Advisory· Published Apr 7, 2026· Updated Apr 17, 2026
CVE-2026-34582
CVE-2026-34582
Description
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/randombit/botan/security/advisories/GHSA-pxcj-9ppx-g86gnvdVendor AdvisoryMitigation
News mentions
0No linked articles in our index yet.