Logo
vulnerabilityCVE-2026-32883
Name
CVE-2026-32883
Source
NVD ( link)Debian ( link)
Description
Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in version 3.11.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
botan
Exploitable

Vulnerability Ratings#


5.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.5.0
Exploitable
yocto
kirkstone
2.19.1
Not Affected
yocto
master
3.12.0
Not Affected
yocto
scarthgap
3.2.0
Exploitable