Improper Verification of Cryptographic Signature in Botan - CVE-2026-32883
Published: April 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass certificate revocation checks.
The vulnerability exists due to improper verification of cryptographic signature in OCSP response verification during X509 path validation when processing OCSP responses. A remote attacker can tamper with an OCSP response body to bypass certificate revocation checks.
Exploitation requires a machine-in-the-middle position between a Botan-based client and an OCSP responder.
Affected software
Fedora
botan3
How to mitigate CVE-2026-32883
botan3 - addressed in versions 3.9.0-3.el10_3, 3.9.0-4.el10_3, 3.9.0-6.fc44, 3.9.0-7.fc44