PatchSiren

Botan Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Botan Project CVE published 2026-04-07

CVE-2026-34580

CVE-2026-34580 is a critical vulnerability in the Botan C++ cryptography library, specifically in version 3.11.0. The vulnerability allows an end entity to be accepted as a trusted root if its DN and subject key identifier match that of a trusted root. This issue arises from a misleading function name 'certificate_known' which was used in an extension of path validation logic. The impact of this vulnerabi [truncated]

CRITICAL Botan Project CVE published 2017-01-30

CVE-2016-9132

CVE-2016-9132 affects Botan releases 1.8.0 through 1.11.33. When BER data is decoded, an integer overflow can cause an incorrect length field to be computed. If an application then trusts and uses that attacker-influenced length value, the result can be memory corruption or another failure. Because the issue can be triggered through untrusted input and the CVSS score is 9.8, this should be treated as a hi [truncated]