#VU125384 Improper Enforcement of Behavioral Workflow in Botan - CVE-2026-34582
Published: April 8, 2026
Botan
Randombit
Description
The vulnerability allows a remote attacker to bypass client certificate authentication.
The vulnerability exists due to improper enforcement of behavioral workflow in the TLS 1.3 implementation when processing ApplicationData records before completion of the handshake. A remote attacker can send application data records before the Finished message to bypass client certificate authentication.
This affects servers attempting to enforce client authentication via certificates, and exploitation involves omitting the Certificate, CertificateVerify, and Finished messages.