CVE-2023-50980: Cryptopp Crypto++
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.
Affected products
- Cryptopp Crypto++: up to and including 8.9.0
Published 2023-12-18. Last modified 2026-06-17.