Dear maintainers,
we are using Crypto++ 8.9.0 as part of our product and have identified that this version is affected by the following vulnerabilities:
BDSA-2024-2515 – High
CVE-2023-50981 – High
CVE-2023-50980 – High
CVE-2023-50979 – Medium
According to the information available, there is a maintained fork cryptopp-modern, which is based on Crypto++ 8.9.0 and incorporates post‑8.9.0 security fixes while remaining compatible with the CryptoPP namespace:
Repository: https://github.com/cryptopp-modern/cryptopp-modern
The latest release (e.g. 2026.4.0) mentions security patches such as the Marvin attack fix (CVE-2023-50979) and additional security improvements.
For our internal vulnerability management and release planning, we would like to request clarification on the following points.
- Remediation plan
1.1. Do you plan to address the following issues in the codebase associated with Crypto++ 8.9.0?
BDSA-2024-2515
CVE‑2023‑50981
CVE‑2023‑50980
CVE‑2023‑50979
1.2. If so, could you indicate whether the fixes will be:
Provided as part of a new Crypto++ release (i.e. beyond 8.9.0), or
Delivered through or aligned with a specific cryptopp-modern release (for example, 2026.4.0)?
- Target version and timelines
2.1. In which tag/release version (Crypto++ and/or cryptopp-modern) do you plan to include the fixes for the above vulnerabilities?
2.2. What is the planned or actual release date for the first version that fully addresses these vulnerabilities, so that downstream users can plan an upgrade?
- Temporary mitigations
3.1. Until a fixed version is available (or adopted), are there any recommended mitigations (e.g. configuration changes, avoidance of specific algorithms/modes, feature disablement) that you suggest to reduce the risk associated with these vulnerabilities?
- Additional information
If there are already advisories, release notes, or documentation describing the status and handling of these CVEs/BDSA in Crypto++ 8.9.0 or cryptopp-modern, kindly point us to them so that we can reference them in our internal security documentation.
Given the High severity rating of several of these issues, a response would be highly appreciated at your earliest convenience.
Thank you in advance for your time and for maintaining this project.
Dear maintainers,
we are using Crypto++ 8.9.0 as part of our product and have identified that this version is affected by the following vulnerabilities:
BDSA-2024-2515 – High
CVE-2023-50981 – High
CVE-2023-50980 – High
CVE-2023-50979 – Medium
According to the information available, there is a maintained fork cryptopp-modern, which is based on Crypto++ 8.9.0 and incorporates post‑8.9.0 security fixes while remaining compatible with the CryptoPP namespace:
Repository: https://github.com/cryptopp-modern/cryptopp-modern
The latest release (e.g. 2026.4.0) mentions security patches such as the Marvin attack fix (CVE-2023-50979) and additional security improvements.
For our internal vulnerability management and release planning, we would like to request clarification on the following points.
1.1. Do you plan to address the following issues in the codebase associated with Crypto++ 8.9.0?
BDSA-2024-2515
CVE‑2023‑50981
CVE‑2023‑50980
CVE‑2023‑50979
1.2. If so, could you indicate whether the fixes will be:
Provided as part of a new Crypto++ release (i.e. beyond 8.9.0), or
Delivered through or aligned with a specific cryptopp-modern release (for example, 2026.4.0)?
2.1. In which tag/release version (Crypto++ and/or cryptopp-modern) do you plan to include the fixes for the above vulnerabilities?
2.2. What is the planned or actual release date for the first version that fully addresses these vulnerabilities, so that downstream users can plan an upgrade?
3.1. Until a fixed version is available (or adopted), are there any recommended mitigations (e.g. configuration changes, avoidance of specific algorithms/modes, feature disablement) that you suggest to reduce the risk associated with these vulnerabilities?
If there are already advisories, release notes, or documentation describing the status and handling of these CVEs/BDSA in Crypto++ 8.9.0 or cryptopp-modern, kindly point us to them so that we can reference them in our internal security documentation.
Given the High severity rating of several of these issues, a response would be highly appreciated at your earliest convenience.
Thank you in advance for your time and for maintaining this project.