Critical severity9.8NVD Advisory· Published Feb 22, 2021· Updated Jun 17, 2026
CVE-2021-24115
CVE-2021-24115
Description
In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*range: <2.17.3
- (no CPE)range: <2.17.3
- Botan/Botandescription
- osv-coords3 versionspkg:rpm/opensuse/Botan&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/Botan&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/Botan&distro=SUSE%20Package%20Hub%2015%20SP2
< 2.10.0-bp152.4.3.1+ 2 more
- (no CPE)range: < 2.10.0-bp152.4.3.1
- (no CPE)range: < 2.10.0-bp152.4.3.1
- (no CPE)range: < 2.10.0-bp152.4.3.1
Patches
Vulnerability mechanics
References
3- github.com/randombit/botan/compare/2.17.2...2.17.3nvdPatchThird Party Advisory
- github.com/randombit/botan/pull/2549nvdPatchThird Party Advisory
- botan.randombit.net/news.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.