PT-2026-29126 · Botan · Botan

·

CVE-2026-32884

·

Published

2026-03-30

·

Updated

2026-04-20

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Botan versions prior to 3.11.0
Description Botan is a C++ cryptography library. When processing X.509 certificate paths with DNS name constraints, a case-sensitive comparison of the Common Name (CN) allowed a certificate to bypass restrictions. Specifically, if an end-entity certificate lacked Subject Alternative Names, Botan incorrectly checked the CN against DNS name constraints, failing to account for mixed-case CNs. This allowed a certificate with a mixed-case CN, like Sub.EVIL.COM, to bypass an excludedSubtrees constraint for evil.com. This behavior violates RFC 5280 standards.
Recommendations Update to version 3.11.0 or later.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-81180
BDU:2026-09630
CVE-2026-32884
GHSA-7C3G-7763-GGJ5
OPENSUSE-SU-2026:20566-1

Affected Products

Botan