CVE-2023-50981: Cryptopp Crypto++
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER public-key data associated with squared odd numbers, such as the square of 268995137513890432434389773128616504853.
Affected products
- Cryptopp Crypto++: up to and including 8.9.0
Published 2023-12-18. Last modified 2026-06-17.