Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Randombit
Randombit botan |
|
| Vendors & Products |
Randombit
Randombit botan |
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0. | |
| Title | Botan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation Bypass | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-30T20:36:30.579Z
Updated: 2026-04-02T14:10:02.578Z
Reserved: 2026-03-16T21:03:44.421Z
Link: CVE-2026-32883
Updated: 2026-04-02T14:09:56.688Z
Status : Undergoing Analysis
Published: 2026-03-30T21:17:09.933
Modified: 2026-04-01T14:24:02.583
Link: CVE-2026-32883