Randombit / Botan
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-44378 | Botan: Quadratic complexity decoding BER indefinite length encodings | MEDIUM | 6.9 | May 27, 2026 |
| CVE-2026-34582 | Botan has a TLS 1.3 certificate authentication bypass | HIGH | 8.7 | Apr 7, 2026 |
| CVE-2026-34580 | Botan has a certificate authentication bypass due to trust anchor confusion | CRITICAL | 9.3 | Apr 7, 2026 |
| CVE-2026-32877 | Botan: Heap Buffer Over-read in SM2 Decryption via Undersized C3 Hash Field | HIGH | 8.2 | Mar 30, 2026 |
| CVE-2026-32883 | Botan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation Bypass | MEDIUM | 6.8 | Mar 30, 2026 |
| CVE-2026-32884 | Botan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 Violation) | MEDIUM | 6.5 | Mar 30, 2026 |
| CVE-2024-39312 | Botan has an Authorization Error due to Name Constraint Decoding Bug | MEDIUM | 5.3 | Jul 8, 2024 |
| CVE-2024-34702 | Botan has a Denial of Service Due to Excessive Name Constraints | MEDIUM | 5.3 | Jul 8, 2024 |
| CVE-2024-34703 | Botan Vulnerable to Denial of Service Due to Overly Large Elliptic Curve Parameters | HIGH | 7.5 | Jun 30, 2024 |
| CVE-2017-2801 | A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparisons which could lead to certificate veri… | CRITICAL | 9.8 | May 24, 2017 |
Showing 1 to 9 of 9 CVEs