CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-34582

Critical · CVSS 9.1

Botan C++ cryptography library — TLS 1.3 client authentication bypass via premature ApplicationData processing

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-841, CWE-166

Description

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.

Search profile — drives PoC discovery

Symbols ApplicationDataFinishedCertificateCertificateVerifyTLS 1.3client authenticationtls13TLS_ServerTLS_Clienthandle_post_handshake_msgprocess_handshake_msgrecord_layerHandshake_State
Keywords CVE-2026-34582Botan TLS 1.3 authentication bypassBotan client certificate bypassGHSA-pxcj-9ppx-g86gBotan ApplicationData Finished bypassBotan 3.11.1 patchBotan TLS handshake bypass PoCBotan CWE-841Botan omit Certificate CertificateVerify Finished
Versions: < 3.11.1

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z