{"id":"AZL-88802","summary":"CVE-2026-44378 affecting package botan2 2.14.0-2","details":"Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such BER encodings were accepted even in structures which are required to be encoded as DER, which prohibits indefinite length encodings. This vulnerability is fixed in 3.12.0.","modified":"2026-08-30T05:24:52Z","published":"2026-05-27T18:16:23Z","upstream":["CVE-2026-44378"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44378"}],"affected":[{"package":{"name":"botan2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/botan2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.14.0-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88802.json"}}],"schema_version":"1.9.0"}