Known Vulnerabilities for Botan by Botan Project
Listed below are 10 of the newest known vulnerabilities associated with "Botan" by "Botan Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34582 json | Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to b... | Not Provided | 2026-04-07 | 2026-04-08 |
| CVE-2026-34580 json | Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it w... | Not Provided | 2026-04-07 | 2026-04-09 |
| CVE-2026-32884 json | Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name const... | Not Provided | 2026-03-30 | 2026-03-31 |
| CVE-2026-32883 json | Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses... | Not Provided | 2026-03-30 | 2026-04-02 |
| CVE-2026-32877 json | Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checke... | Not Provided | 2026-03-30 | 2026-03-31 |
| CVE-2022-43705 json | In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introd... | 9.1 - CRITICAL | 2022-11-27 | 2022-12-01 |
| CVE-2021-40529 json | The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery beca... | 5.9 - MEDIUM | 2021-09-06 | 2023-11-07 |
| CVE-2021-24115 json | In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58,... | 9.8 - CRITICAL | 2021-02-22 | 2021-02-26 |
| CVE-2018-20187 json | A side-channel issue was discovered in Botan before 2.9.0. An attacker capable of precisely measuring the time taken for ECC ... | 5.9 - MEDIUM | 2019-03-08 | 2019-03-12 |
| CVE-2018-12435 json | Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the H... | 5.9 - MEDIUM | 2018-06-15 | 2018-08-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Botan Project | Botan | 2.9.0 | |||
| Application | Botan Project | Botan | 2.8.0 | |||
| Application | Botan Project | Botan | 2.7.0 | |||
| Application | Botan Project | Botan | 2.6.0 | |||
| Application | Botan Project | Botan | 2.5.0 | |||
| Application | Botan Project | Botan | 2.4.0 | |||
| Application | Botan Project | Botan | 2.3.0 | |||
| Application | Botan Project | Botan | 2.2.0 | |||
| Application | Botan Project | Botan | 2.17.3 | |||
| Application | Botan Project | Botan | 2.17.2 | |||
| Application | Botan Project | Botan | 2.17.1 | |||
| Application | Botan Project | Botan | 2.17.0 | |||
| Application | Botan Project | Botan | 2.16.0 | |||
| Application | Botan Project | Botan | 2.15.0 | |||
| Application | Botan Project | Botan | 2.14.0 | |||
| Application | Botan Project | Botan | 2.13.0 | |||
| Application | Botan Project | Botan | 2.12.1 | |||
| Application | Botan Project | Botan | 2.12.0 | |||
| Application | Botan Project | Botan | 2.11.0 | |||
| Application | Botan Project | Botan | 2.10.0 |