PT-2026-29124 · Botan · Botan

Harutokimura

·

Published

2026-03-30

·

Updated

2026-03-31

·

CVE-2026-32877

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Botan versions 2.3.0 through 3.10.9
Description Botan is a C++ cryptography library. During SM2 decryption, the code that checks the authentication code value (C3) does not verify the encoded value's length before comparison. This can lead to a heap over-read of up to 31 bytes from an invalid ciphertext, potentially causing a crash or undefined behavior.
Recommendations Update to version 3.11.0 or later.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2026-07567
CVE-2026-32877
GHSA-7JJ6-4R42-W9H6

Affected Products

Botan