Botan
This hub aggregates every CVE we track for Botan, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
37
CVEs tracked
9
Critical
16
High
0
In CISA KEV
Severity distribution
HIGH16MEDIUM12CRITICAL9
Monthly trend
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
2
1
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Botan.
- CVE-2026-44378Botan: Quadratic complexity decoding BER indefinite length encodings7.5
- CVE-2026-34582Botan has a TLS 1.3 certificate authentication bypass9.1
- CVE-2026-34580Botan has a certificate authentication bypass due to trust anchor confusion7.5
- CVE-2026-32877Botan: Heap Buffer Over-read in SM2 Decryption via Undersized C3 Hash Field8.2
- CVE-2026-32883Botan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation Bypass5.9
- CVE-2026-32884Botan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 Violation)5.9
- CVE-2024-50383Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can b...5.9
- CVE-2024-50382Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR wit...5.9
- CVE-2024-39312Botan has an Authorization Error due to Name Constraint Decoding Bug5.3
- CVE-2024-34702Botan has a Denial of Service Due to Excessive Name Constraints5.3
- CVE-2024-34703Botan Vulnerable to Denial of Service Due to Overly Large Elliptic Curve Parameters7.5
- CVE-2017-7252bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.7.5
- CVE-2022-43705In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).9.1
- CVE-2021-40529The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain d...5.9
- CVE-2021-24115In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).9.8
Product normalization is registry-driven with AI assist and human review. How it works