CVE-2015-7826 describes an improper wildcard matching vulnerability in Botan 1.11.x before 1.11.22, affecting the botan_project. This critical vulnerability (CVSS 9.8) allows remote attackers to potentially have a significant impact on confidentiality, integrity, and availability by using a valid X.509 certificate to bypass hostname validation, as demonstrated by *.example.com matching bar.foo.example.com. While there is no known active exploitation or publicly available exploit code (Metasploit, Nuclei, ExploitDB), the CVE has garnered substantial community discussion with 10 mentions, indicating awareness despite a lack of media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.11.21CPE matchmatch criteria | cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.