Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cryptopp

First CVE: Jul 1, 2015Active for: 11 yearsTotal CVEs: 13
30.7
VTI Score
Low

Crypto++ is a widely embedded C++ cryptographic library deployed across numerous applications and systems, making its vulnerability footprint significant despite a narrow product focus. The recurring weaknesses—including sensitive-information exposure, observable timing or side-channel discrepancies, improper input validation, and infinite-loop conditions—reflect the parsing, algorithm-implementation, and constant-time-operation demands of a cryptography library. Defenders should inventory products that depend on this library and track its releases closely, since a flaw in a foundational crypto component can propagate broadly; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cryptopp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2015
11 years ago
Most Recent CVE
Dec 18, 2023
949 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-3995HIGH
The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler
Feb 13, 20177.525NONO
CVE-2016-7544HIGH
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later
Jan 30, 20177.525NONO
CVE-2019-14318MEDIUM
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousan
Jul 30, 20195.922NONO
CVE-2016-7420MEDIUM
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use,
Sep 16, 20165.922NONO
CVE-2021-40530MEDIUM
The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the
Sep 6, 20215.921NONO
CVE-2023-50981HIGH
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER public-key data associated with squared odd
Dec 18, 20237.520NONO
CVE-2023-50980HIGH
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of ea
Dec 18, 20237.520NONO
CVE-2021-43398MEDIUM
Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause
Nov 4, 20215.320NONO
CVE-2017-9434MEDIUM
Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.
Jun 5, 20175.320NONO
CVE-2016-9939HIGH
Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on the length field of the ASN.1 obj
Jan 30, 20177.520NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
54%
46%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network12 (92.3%)
Unknown1 (7.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (61.5%)
High4 (30.8%)
Unknown1 (7.7%)
User Interaction
None12 (92.3%)
Unknown1 (7.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (92.3%)
Unknown1 (7.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cryptopp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cryptopp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cryptopp's Products

View all 1 CNAs →

Top CWEs