Skip to content

Security vulnerabilities in Crypto++ 8.9.0 (CVE-2023-50981, CVE-2023-50980, CVE-2023-50979) and clarification on remediation plan #21

Description

@akrattan

Dear maintainers,

we are using Crypto++ 8.9.0 as part of our product and have identified that this version is affected by the following vulnerabilities:

BDSA-2024-2515 – High

CVE-2023-50981 – High

CVE-2023-50980 – High

CVE-2023-50979 – Medium

According to the information available, there is a maintained fork cryptopp-modern, which is based on Crypto++ 8.9.0 and incorporates post‑8.9.0 security fixes while remaining compatible with the CryptoPP namespace:

Repository: https://github.com/cryptopp-modern/cryptopp-modern

The latest release (e.g. 2026.4.0) mentions security patches such as the Marvin attack fix (CVE-2023-50979) and additional security improvements.

For our internal vulnerability management and release planning, we would like to request clarification on the following points.

  1. Remediation plan

1.1. Do you plan to address the following issues in the codebase associated with Crypto++ 8.9.0?

BDSA-2024-2515

CVE‑2023‑50981

CVE‑2023‑50980

CVE‑2023‑50979

1.2. If so, could you indicate whether the fixes will be:

Provided as part of a new Crypto++ release (i.e. beyond 8.9.0), or

Delivered through or aligned with a specific cryptopp-modern release (for example, 2026.4.0)?

  1. Target version and timelines

2.1. In which tag/release version (Crypto++ and/or cryptopp-modern) do you plan to include the fixes for the above vulnerabilities?

2.2. What is the planned or actual release date for the first version that fully addresses these vulnerabilities, so that downstream users can plan an upgrade?

  1. Temporary mitigations

3.1. Until a fixed version is available (or adopted), are there any recommended mitigations (e.g. configuration changes, avoidance of specific algorithms/modes, feature disablement) that you suggest to reduce the risk associated with these vulnerabilities?

  1. Additional information

If there are already advisories, release notes, or documentation describing the status and handling of these CVEs/BDSA in Crypto++ 8.9.0 or cryptopp-modern, kindly point us to them so that we can reference them in our internal security documentation.

Given the High severity rating of several of these issues, a response would be highly appreciated at your earliest convenience.

Thank you in advance for your time and for maintaining this project.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions