Improper Enforcement of Behavioral Workflow in Botan - CVE-2026-34582
Published: April 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass client certificate authentication.
The vulnerability exists due to improper enforcement of behavioral workflow in the TLS 1.3 implementation when processing ApplicationData records before completion of the handshake. A remote attacker can send application data records before the Finished message to bypass client certificate authentication.
This affects servers attempting to enforce client authentication via certificates, and exploitation involves omitting the Certificate, CertificateVerify, and Finished messages.
Affected software
Fedora
botan3
How to mitigate CVE-2026-34582
botan3 - addressed in versions 3.9.0-3.el10_3, 3.9.0-4.el10_3, 3.9.0-6.fc44, 3.9.0-7.fc44