Improper Certificate Validation in Botan - CVE-2026-32884
Published: April 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass DNS name constraints enforcement.
The vulnerability exists due to improper certificate validation in X.509 certificate path processing when validating a certificate chain with DNS excludedSubtrees constraints and an end-entity certificate that has a mixed-case CN and no subject alternative name. A remote attacker can present a specially crafted certificate to bypass DNS name constraints enforcement.
This issue is relevant when nameConstraints are used to restrict allowable DNS names.
Affected software
Fedora
botan3
How to mitigate CVE-2026-32884
botan3 - addressed in versions 3.9.0-3.el10_3, 3.9.0-4.el10_3, 3.9.0-6.fc44, 3.9.0-7.fc44