Bug 2453204 (CVE-2026-32883) - CVE-2026-32883 Botan: Botan: Compromised certificate validation integrity via unverified OCSP response signatures
Summary: CVE-2026-32883 Botan: Botan: Compromised certificate validation integrity via...
Keywords:
Status: NEW
Alias: CVE-2026-32883
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2453750 2453751 2453752 2453753 2453754 2453755
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-30 21:02 UTC by OSIDB Bzimport
Modified: 2026-04-01 06:53 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-30 21:02:28 UTC
Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.


Note You need to log in before you can comment on or make changes to this bug.