PT-2026-42855 · Botan · Botan

·

CVE-2026-44378

·

Published

2026-05-12

·

Updated

2026-06-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Botan versions prior to 3.12.0
Description Certain patterns of indefinite length encodings in Basic Encoding Rules (BER) data can cause quadratic behavior in the parser, leading to a denial of service. These BER encodings were accepted even in structures required to be encoded as Distinguished Encoding Rules (DER), which specifically prohibit indefinite length encodings.
Recommendations Update to version 3.12.0.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44378
GHSA-7Q2V-3G27-6G3J

Affected Products

Botan