CVE-2016-2850: Botan Project Botan

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.

Affected products

  • Botan Project Botan: version 1.11.0 only; version 1.11.1 only; version 1.11.2 only; version 1.11.3 only; version 1.11.4 only; version 1.11.5 only; …
  • Fedoraproject Fedora: version 24 only

Published 2016-05-13. Last modified 2026-06-17.