Botan
Botan Project · 35 CVEs
Botan: Quadratic complexity decoding BER indefinite length encodings
May 27, 2026
Botan has a TLS 1.3 certificate authentication bypass
Apr 7, 2026
Botan has a certificate authentication bypass due to trust anchor confusion
Apr 7, 2026
Botan: Heap Buffer Over-read in SM2 Decryption via Undersized C3 Hash Field
Mar 30, 2026
Botan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation Bypass
Mar 30, 2026
Botan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 Violation)
Mar 30, 2026
Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/…
Oct 23, 2024
Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/util…
Oct 23, 2024
Botan has an Authorization Error due to Name Constraint Decoding Bug
Jul 8, 2024
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 chara…
Nov 3, 2023
In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was…
Nov 27, 2022
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recover…
Sep 6, 2021
In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, b…
Feb 22, 2021
A side-channel issue was discovered in Botan before 2.9.0. An attacker capable of precisely measuring the time taken fo…
Mar 8, 2019
Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of…
Jun 15, 2018
An issue was discovered in Botan 1.11.32 through 2.x before 2.6.0. An off-by-one error when processing malformed TLS-CB…
Apr 12, 2018
Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as…
Apr 2, 2018
A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2…
Sep 26, 2017
A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparis…
May 24, 2017
The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified i…
Apr 10, 2017
The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to…
Apr 10, 2017
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers…
Apr 10, 2017
botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service…
Apr 10, 2017
botan 1.11.x before 1.11.22 makes it easier for remote attackers to decrypt TLS ciphertext data via a padding-oracle at…
Apr 10, 2017
In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect…
Jan 30, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-44378 | Botan: Quadratic complexity decoding BER indefinite length encodings | MEDIUM | 0.46% | May 27, 2026 |
| CVE-2026-34582 | Botan has a TLS 1.3 certificate authentication bypass | HIGH | 0.38% | Apr 7, 2026 |
| CVE-2026-34580 | Botan has a certificate authentication bypass due to trust anchor confusion | CRITICAL | 0.32% | Apr 7, 2026 |
| CVE-2026-32877 | Botan: Heap Buffer Over-read in SM2 Decryption via Undersized C3 Hash Field | HIGH | 0.50% | Mar 30, 2026 |
| CVE-2026-32883 | Botan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation Bypass | MEDIUM | 0.19% | Mar 30, 2026 |
| CVE-2026-32884 | Botan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 Violation) | MEDIUM | 0.20% | Mar 30, 2026 |
| CVE-2024-50383 | Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-P… | MEDIUM | 0.55% | Oct 23, 2024 |
| CVE-2024-50382 | Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. T… | MEDIUM | 0.55% | Oct 23, 2024 |
| CVE-2024-39312 | Botan has an Authorization Error due to Name Constraint Decoding Bug | MEDIUM | 0.27% | Jul 8, 2024 |
| CVE-2017-7252 | bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attacke… | HIGH | 0.32% | Nov 3, 2023 |
| CVE-2022-43705 | In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 20… | CRITICAL | 0.45% | Nov 27, 2022 |
| CVE-2021-40529 | The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between tw… | MEDIUM | 1.53% | Sep 6, 2021 |
| CVE-2021-24115 | In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex). | CRITICAL | 1.98% | Feb 22, 2021 |
| CVE-2018-20187 | A side-channel issue was discovered in Botan before 2.9.0. An attacker capable of precisely measuring the time taken for ECC key generation may be able to deri… | MEDIUM | 1.52% | Mar 8, 2019 |
| CVE-2018-12435 | Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP, rel… | MEDIUM | 0.50% | Jun 15, 2018 |
| CVE-2018-9860 | An issue was discovered in Botan 1.11.32 through 2.x before 2.6.0. An off-by-one error when processing malformed TLS-CBC ciphertext could cause the receiving s… | HIGH | 1.36% | Apr 12, 2018 |
| CVE-2018-9127 | Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, under RFC 6125… | CRITICAL | 0.93% | Apr 2, 2018 |
| CVE-2017-14737 | A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover… | MEDIUM | 0.32% | Sep 26, 2017 |
| CVE-2017-2801 | A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparisons which could lead to certificate veri… | CRITICAL | 1.32% | May 24, 2017 |
| CVE-2016-6879 | The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call with more tha… | HIGH | 0.56% | Apr 10, 2017 |
| CVE-2016-6878 | The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to have unspecified impact via vectors rel… | CRITICAL | 1.23% | Apr 10, 2017 |
| CVE-2015-7826 | botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X… | CRITICAL | 1.11% | Apr 10, 2017 |
| CVE-2015-7825 | botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service (infinite loop and memory consumption)… | HIGH | 1.04% | Apr 10, 2017 |
| CVE-2015-7824 | botan 1.11.x before 1.11.22 makes it easier for remote attackers to decrypt TLS ciphertext data via a padding-oracle attack against TLS CBC ciphersuites. | HIGH | 1.69% | Apr 10, 2017 |
| CVE-2016-9132 | In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API ca… | CRITICAL | 1.98% | Jan 30, 2017 |
Showing 1 to 25 of 35 CVEs