Junglewise Threat Intelligence

CVE-2026-34582: Botan TLS 1.3 client authentication bypass

CVE-2026-34582 · Severity: critical · CVSS 9.1 · Published 2026-04-07

Technologies: Red Hat Enterprise Linux 10, Botan Project Botan. Vendors: Red Hat, Botan Project.

Executive brief

Botan is a widely used software library that provides cryptographic functions for securing communications. A flaw in its implementation of the TLS 1.3 protocol allows an attacker to bypass mandatory security checks that verify a user's identity. This could allow unauthorized individuals to access protected systems or data without providing the required digital certificates.

Technical details

A vulnerability exists in Botan's TLS 1.3 stack due to improper enforcement of the handshake behavioral workflow (CWE-841). The implementation allowed the processing of ApplicationData records before the Finished message was received and verified. An unauthenticated remote attacker can exploit this by omitting the Certificate, CertificateVerify, and Finished messages during the handshake. This effectively bypasses mutual TLS (mTLS) authentication, allowing the attacker to submit application-layer data to a server that requires client certificate authentication. The issue is resolved in Botan version 3.11.1.

Affected products

  • randombit Botan >= 3.0.0, < 3.11.1
  • Red Hat Red Hat Enterprise Linux 10 Affected

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory: Vendor advisory GHSA-pxcj-9ppx-g86g published
  • 2026-04-07: patched: Fixed in version 3.11.1

References

Related threats