Record summary

CVE-2026-34582 has a selected CVSS score of 8.7 (high).

Description

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 8, 2026 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10rust-sequoia-sq

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10rust-sequoia-sqv

Default status: affected

CVE ListVersion data not supplied
CVE List< 3.11.1affected

References

4