CVE-2026-34580Disclosure(botan_project / botan)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the cert it found and the cert it was passed were actually the same certificate. In 3.11.0 an extension of path validation logic was made which assumed that certificate_known only returned true if the certificates were in fact identical. The impact is that if an end entity certificate is presented, and its DN (and subject key identifier, if set) match that of any trusted root, the end entity certificate is accepted immediately as if it itself were a trusted root. , This vulnerability is fixed in 3.11.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • botan

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-08)
  • 3 total mentions across 2 days

Affected systems

Products
botan

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-07: 1Mentions · 2026-04-08: 2Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 204-0704-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-04-082
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34580 Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in th… https://www.cve.org/CVERecord?id=CVE-2026-34580

    Post summary

    The text discloses a logic flaw in Botan’s certificate store where Certificate_Store::certificate_known incorrectly returns true for any certificate, potentially affecting certificate validation.

    00000140
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34580 Certificate Validation Bypass in Botan C++ Cryptography Library 3... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34580 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post announces a newly disclosed CVE‑2026‑34580 involving a certificate validation bypass in the Botan C++ cryptography library, but provides no evidence of an exploit, tool, patch, or active attacks.

    0000039
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34580: Botan has a certificate authenti... DN collision lets any cert masquerade as trusted root - attackers can craft certs matching CA distinguished names for i... https://zerodaysignal.com/vulnerability/CVE-2026-34580 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Announcement of CVE-2026-34580, a DN collision flaw in Botan that allows forging of trusted root certificates; no exploit tools, active exploitation, or patches are mentioned.

    0000058
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbotan_projectbotan3.11.0--

Explore more