Skip to main content

Vendor/product archive

botan_project / botan CVEs

Beta · best-effort

35 CVEs tagged to botan_project / botan9 Critical, 14 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2026-44378

Published May 27, 2026

Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a deni…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34582

Published Apr 7, 2026

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being receiv…

CVSS 8.7 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-34580

Published Apr 7, 2026

Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-32884

Published Mar 30, 2026

Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name constraints which restrict the set of allowable DNS names,…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32883

Published Mar 30, 2026

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but crit…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32877

Published Mar 30, 2026

Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C3) failed to check t…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-50383

Published Oct 23, 2024

Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519).…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50382

Published Oct 23, 2024

Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch ins…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39312

Published Jul 8, 2024

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the p…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7252

Published Nov 3, 2023

bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43705

Published Nov 27, 2022

In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-24115

Published Feb 22, 2021

In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-20187

Published Mar 8, 2019

A side-channel issue was discovered in Botan before 2.9.0. An attacker capable of precisely measuring the time taken for ECC key generation may be able to derive information about…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12435

Published Jun 15, 2018

Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP, related to dsa/dsa.cpp,…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9860

Published Apr 12, 2018

An issue was discovered in Botan 1.11.32 through 2.x before 2.6.0. An off-by-one error when processing malformed TLS-CBC ciphertext could cause the receiving side to include in th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9127

Published Apr 2, 2018

Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, under RFC 6125 rules, they should…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14737

Published Sep 26, 2017

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about R…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2801

Published May 24, 2017

A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparisons which could lead to certificate verification issues and…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6879

Published Apr 10, 2017

The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call with more than one Key_Usage set…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6878

Published Apr 10, 2017

The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to have unspecified impact via vectors related to undefined be…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7826

Published Apr 10, 2017

botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7825

Published Apr 10, 2017

botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a certificate wi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7824

Published Apr 10, 2017

botan 1.11.x before 1.11.22 makes it easier for remote attackers to decrypt TLS ciphertext data via a padding-oracle attack against TLS CBC ciphersuites.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9132

Published Jan 30, 2017

In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the re…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 35 CVEsPage 1 of 2