randombit.botan is vulnerable to Improper Access Control
67
Medium Risk
Affected versions of this package are vulnerable to a name constraints bypass in DNS name validation due to improper handling of case sensitivity. The implementation performs case-sensitive comparisons of DNS names, including when falling back to the certificate’s Common Name (CN), allowing crafted inputs with differing letter casing to evade constraint checks. This may result in the acceptance of certificates that should be rejected, weakening certificate validation guarantees.
You are affected if you are using a version that falls within the vulnerable range.
randombit.botan is vulnerable to Improper Access Control in versions 0.0.1 - 3.10.0.
Upgrade the randombit.botan library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant