← Vulnerability feed

Vulnerability record · CVE-2023-36660 · published 25 June 2023

CVE-2023-36660: Nettle project nettle out-of-bounds write vulnerability

Nettle Project · Nettle

The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.

9.8 CVSS 3.1 Critical EPSS 1.0% · top 37.7% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-36660 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-8805Nettle project nettle vulnerabilityThe ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implement…EPSS 2.8%9.8CVE-2015-8804Nettle project nettle vulnerabilityx86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-…EPSS 3.9%9.8CVE-2015-8803Nettle project nettle vulnerabilityThe ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implement…EPSS 4.2%8.1CVE-2021-20305Nettle project nettle broken cryptographic algorithm vulnerabilityA flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the El…EPSS 1.7%7.5CVE-2021-3580Nettle project nettle improper input validation vulnerabilityA flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a mani…EPSS 2.7%7.5CVE-2016-6489Redhat enterprise linux desktop observable discrepancy vulnerabilityThe RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.EPSS 5.0%5.7CVE-2018-16869Nettle project nettle observable discrepancy vulnerabilityA Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 dat…EPSS 1.5%8.8CVE-2026-86950Apple ipados out-of-bounds write vulnerabilityAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, …KEVEPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2023-36660), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.