CVE-2016-9132: Botan Project Botan

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.

Affected products

  • Botan Project Botan: version 1.8.0 only; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; version 1.8.4 only; version 1.8.5 only; …

Published 2017-01-30. Last modified 2026-06-17.