Improper Certificate Validation in Botan - CVE-2026-32884

 

Improper Certificate Validation in Botan - CVE-2026-32884

Published: April 8, 2026


Vulnerability identifier: #VU125382
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-32884
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass DNS name constraints enforcement.

The vulnerability exists due to improper certificate validation in X.509 certificate path processing when validating a certificate chain with DNS excludedSubtrees constraints and an end-entity certificate that has a mixed-case CN and no subject alternative name. A remote attacker can present a specially crafted certificate to bypass DNS name constraints enforcement.

This issue is relevant when nameConstraints are used to restrict allowable DNS names.


Affected software

Botan
Fedora
botan3

How to mitigate CVE-2026-32884

Install security update from vendor's website.

Botan - update to 3.11.0
botan3 - addressed in versions 3.9.0-3.el10_3, 3.9.0-4.el10_3, 3.9.0-6.fc44, 3.9.0-7.fc44

External References

Related Security Bulletins