Logo
vulnerabilityCVE-2026-44378
Name
CVE-2026-44378
Source
NVD ( link)Debian ( link)
Description
Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such BER encodings were accepted even in structures which are required to be encoded as DER, which prohibits indefinite length encodings. This vulnerability is fixed in 3.12.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
botan
Exploitable

Vulnerability Ratings#


6.9
CVSSv4
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.5.0
Exploitable
buildroot
master
3.5.0
Exploitable
yocto
kirkstone
2.19.1
Exploitable
yocto
master
3.12.0
Not Affected