CVE-2026-32883 is a vulnerability in the Botan C++ cryptography library (versions 3.0.0 to 3.10.x) that stems from a critical omission in X509 path validation, where OCSP response signatures were not verified. This flaw could allow an attacker to bypass certificate revocation checks. With a CVSS score of 5.9 (Medium), the vulnerability has a network attack vector and high integrity impact, potentially enabling systems to trust revoked certificates, though successful exploitation requires high attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.11.0CPE matchmatch criteria | cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.