CVE-2016-2849: Botan Project Botan

High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.

Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.

Affected products

  • Botan Project Botan: version 1.10.12 only; version 1.11.0 only; version 1.11.1 only; version 1.11.2 only; version 1.11.3 only; version 1.11.4 only; …
  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 24 only

Published 2016-05-13. Last modified 2026-06-17.