Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-34702

17
FAUCET Score

CVE-2024-34702 is a denial-of-service vulnerability affecting the Botan C++ cryptography library, specifically versions prior to 3.5.0 and 2.19.5. An attacker could exploit a quadratic complexity issue in X.509 certificate name constraint checking by presenting a certificate chain with numerous names and a CA certificate with many name constraints, leading to a denial of service. With a CVSS score of 5.3 (Medium), this vulnerability has a network attack vector, low attack complexity, and impacts availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
RandombitBotan
< 2.19.5, >= 3.0.0, < 3.5.0CNA affected

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.84%
Probability of exploitation in next 30 days
EPSS Percentile
54.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0084 is in the 34th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / randombit/botan/commit/21dccc8fef18c165ba3301d850ac61521f85637e
github.com / randombit/botan/commit/39535f13c322f56aa3da2f44b2b6abb8619a82ac
github.com / randombit/botan/commit/477822a2d10f02d8ba46c9d8a5132f25843f5cc1
github.com / randombit/botan/commit/7606d70d3a2ac7114476ec2651ca0243c4536fdf
github.com / randombit/botan/commit/c3264821b9f6286ee4e6e3e06826f6b7177e6d41
github.com / randombit/botan/commit/ff704b12e6fa351aaedd07bffdc91722e84586b8
github.com / randombit/botan/pull/4034
github.com / randombit/botan/pull/4045
github.com / randombit/botan/pull/4047
github.com / randombit/botan/pull/4052
github.com / randombit/botan/pull/4186
github.com / randombit/botan/pull/4187
github.com / randombit/botan/security/advisories/GHSA-5gg9-hqpr-r58j