Intel

AIKIDO-2026-10396

randombit.botan is vulnerable to Improper Access Control

Improper Access ControlCVE-2026-32884 Published Mar 19, 2026

67

Medium Risk

This Affects:

C++randombit.botan
0.0.1 - 3.10.0
Fixed in 3.11.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a name constraints bypass in DNS name validation due to improper handling of case sensitivity. The implementation performs case-sensitive comparisons of DNS names, including when falling back to the certificate’s Common Name (CN), allowing crafted inputs with differing letter casing to evade constraint checks. This may result in the acceptance of certificates that should be rejected, weakening certificate validation guarantees.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

randombit.botan is vulnerable to Improper Access Control in versions 0.0.1 - 3.10.0.

How to fix this

Upgrade the randombit.botan library to a patch version.