5.9
CVE-2026-32883
- EPSS 0.02%
- Veröffentlicht 30.03.2026 20:36:30
- Zuletzt bearbeitet 13.04.2026 13:54:57
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Botan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation Bypass
Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Botan Project ≫ Botan Version >= 3.0.0 < 3.11.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.05 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.