# CVE-2026-34582

## Summary

- **CVE ID:** CVE-2026-34582
- **Severity:** HIGH
- **CVSS Score:** 9.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-841
- **Published:** Apr 7, 2026
- **Last Modified:** Jul 15, 2026

## Description

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.

## Affected Products

- randombit — botan (< 3.11.1)

## References

- [CNA](https://github.com/randombit/botan/security/advisories/GHSA-pxcj-9ppx-g86g)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-34582)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2456285)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34582.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 14.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._