CVE-2023-50981: Cryptopp Crypto++

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER public-key data associated with squared odd numbers, such as the square of 268995137513890432434389773128616504853.

Affected products

  • Cryptopp Crypto++: up to and including 8.9.0

Published 2023-12-18. Last modified 2026-06-17.