CVE-2026-34582
Critical · CVSS 9.1Botan C++ cryptography library — TLS 1.3 client authentication bypass via premature ApplicationData processing
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-841, CWE-166
Description
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Search profile — drives PoC discovery
Symbols ApplicationDataFinishedCertificateCertificateVerifyTLS 1.3client authenticationtls13TLS_ServerTLS_Clienthandle_post_handshake_msgprocess_handshake_msgrecord_layerHandshake_State
Keywords CVE-2026-34582Botan TLS 1.3 authentication bypassBotan client certificate bypassGHSA-pxcj-9ppx-g86gBotan ApplicationData Finished bypassBotan 3.11.1 patchBotan TLS handshake bypass PoCBotan CWE-841Botan omit Certificate CertificateVerify Finished
Versions: < 3.11.1
References
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z