Inefficient Algorithmic Complexity in Botan - CVE-2026-44378
Published: May 7, 2026
Botan
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the BER parser when parsing indefinite length encodings in ASN.1 encoded data. A remote attacker can send specially crafted ASN.1 data to cause a denial of service.
This can be triggered with ASN.1 encoded inputs such as an X.509 certificate or OCSP response.