Inefficient Algorithmic Complexity in Botan - CVE-2026-44378
Published: May 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the BER parser when parsing indefinite length encodings in ASN.1 encoded data. A remote attacker can send specially crafted ASN.1 data to cause a denial of service.
This can be triggered with ASN.1 encoded inputs such as an X.509 certificate or OCSP response.
Affected software
Debian Linux
Fedora
botan3 (Debian package)
botan3
How to mitigate CVE-2026-44378
botan3 (Debian package) - update to 3.12.0+dfsg-2~deb13u1
botan3 - update to 3.12.0-1.fc46