PT-2026-29124 · Botan · Botan

·

CVE-2026-32877

·

Published

2026-03-30

·

Updated

2026-03-31

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Botan versions 2.3.0 through 3.10.9
Description Botan is a C++ cryptography library. During SM2 decryption, the code that checks the authentication code value (C3) does not verify the encoded value's length before comparison. This can lead to a heap over-read of up to 31 bytes from an invalid ciphertext, potentially causing a crash or undefined behavior.
Recommendations Update to version 3.11.0 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07567
CVE-2026-32877
GHSA-7JJ6-4R42-W9H6

Affected Products

Botan