CVE-2015-7827: Botan Project Botan

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.

Affected products

  • Botan Project Botan: up to and including 1.10.13; version 1.11.0 only; version 1.11.1 only; version 1.11.2 only; version 1.11.3 only; version 1.11.4 only; …
  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 24 only

Published 2016-05-13. Last modified 2026-06-17.