access.redhat.comvdb entry
https://access.redhat.com/security/cve/CVE-2026-34582 CVE-2026-34582
HIGH
Botan has a TLS 1.3 certificate authentication bypass
Record summary
CVE-2026-34582 has a selected CVSS score of 8.7 (high).
Description
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 8, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
| CVE List | < 3.11.1 | affected | |
References
4RHBZ#2456285issue tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2456285 github.comConfirmation
https://github.com/randombit/botan/security/advisories/GHSA-pxcj-9ppx-g86g security.access.redhat.comx_sadp csaf vex
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34582.json