Junglewise Threat Intelligence

CVE-2026-34580: Botan certificate validation bypass in Certificate_Store

CVE-2026-34580 · Severity: high · CVSS 7.5 · Published 2026-04-07

Technologies: Botan Project Botan, Red Hat Enterprise Linux 10. Vendors: Botan Project, Red Hat.

Executive brief

Botan is a widely used software library that provides cryptographic functions like encryption and digital certificate verification. A flaw in how the library checks trusted certificates allows a malicious certificate to be incorrectly accepted as a trusted authority. This could allow an attacker to impersonate legitimate services or intercept secure communications without triggering security warnings.

Technical details

A certificate validation bypass exists in Botan 3.11.0 due to trust anchor confusion in the Certificate_Store::certificate_known function. The function incorrectly returned a success boolean if a certificate's Distinguished Name (DN) and Subject Key Identifier (SKI) matched an entry in the trusted store, without verifying that the actual certificate data was identical. Combined with new path validation logic in version 3.11.0, this allows an end-entity certificate to be treated as a trusted root if its metadata matches a known root. An unauthenticated remote attacker can exploit this to bypass X.509 chain validation. The issue is resolved in Botan version 3.11.1.

Affected products

  • randombit Botan 3.11.0
  • Red Hat Red Hat Enterprise Linux 10 unspecified

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory
  • 2026-04-07: patched: Fixed in version 3.11.1

References

Related threats