Improper Enforcement of Behavioral Workflow in Botan - CVE-2026-34582

 

Improper Enforcement of Behavioral Workflow in Botan - CVE-2026-34582

Published: April 8, 2026


Vulnerability identifier: #VU125384
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34582
CWE-ID: CWE-841
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass client certificate authentication.

The vulnerability exists due to improper enforcement of behavioral workflow in the TLS 1.3 implementation when processing ApplicationData records before completion of the handshake. A remote attacker can send application data records before the Finished message to bypass client certificate authentication.

This affects servers attempting to enforce client authentication via certificates, and exploitation involves omitting the Certificate, CertificateVerify, and Finished messages.


Affected software

Botan
Fedora
botan3

How to mitigate CVE-2026-34582

Install security update from vendor's website.

Botan - update to 3.11.1
botan3 - addressed in versions 3.9.0-3.el10_3, 3.9.0-4.el10_3, 3.9.0-6.fc44, 3.9.0-7.fc44

External References

Related Security Bulletins