CVE-2023-50979: Cryptopp Crypto++

Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.

Affected products

  • Cryptopp Crypto++: up to and including 8.9.0

Published 2023-12-18. Last modified 2026-06-17.