CVE-2023-50980: Cryptopp Crypto++

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.

Affected products

  • Cryptopp Crypto++: up to and including 8.9.0

Published 2023-12-18. Last modified 2026-06-17.