Botan disclosed CVE-2026-34580 / GHSA-v782-6fq4-q827, a certificate authentication bypass in Botan 3.11.0 that can cause X.509 verification to incorrectly trust an attacker-controlled end-entity certificate. The flaw stems from Certificate_Store::certificate_known, which returned true when a stored certificate merely matched the presented certificate’s distinguished name and, if present, subject key identifier, instead of confirming the two certificates were identical.
Because path validation logic introduced in Botan 3.11.0 treated that result as proof of certificate identity, an end-entity certificate could be accepted immediately as a trusted root if it reused the DN and optional subject key identifier of a legitimate trust anchor. Botan fixed the issue in version 3.11.1, and the advisory credits Nicholas Carlini with Claude, Anthropic for reporting the vulnerability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On April 7, 2026, Botan publicly disclosed the certificate authentication bypass vulnerability in advisory GHSA-v782-6fq4-q827 / CVE-2026-34580. The project fixed the issue in Botan 3.11.1.
The Botan advisory credits Nicholas Carlini with Claude, Anthropic for reporting the certificate authentication bypass issue affecting Botan 3.11.0.
Botan 3.11.0 included updated path validation logic that incorrectly treated Certificate_Store::certificate_known as proof of certificate identity. This created a condition where an end-entity certificate matching a trusted root's distinguished name and optional subject key identifier could be accepted as a trusted root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.