Description
Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who holds a captured CMS EnvelopedData message, and who can submit many modified messages to an application that decrypts them with the recipient's RSA private key and reveals how decryption failed, to recover the captured message's content-encryption key and so its content, via a Bleichenbacher-style adaptive chosen-ciphertext attack, because a key-transport ciphertext with invalid PKCS#1 v1.5 padding is rejected during unwrap with a distinct "bad padding in message." CmsException instead of being replaced by a random key, so it can be told apart from a correctly padded ciphertext, which fails only later at content decryption.
Published: 2026-10-02
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Compromise
Action: Immediate Patch
AI Analysis

Impact

A padding oracle exists in the CMS RSA PKCS#1 v1.5 key‑transport unwrap process that allows an attacker who has captured a CMS EnvelopedData message to perform a Bleichenbacher‑style adaptive chosen‑ciphertext attack. By submitting many modified ciphertexts to an application that uses the recipient’s RSA private key, the attacker can distinguish a "bad padding" error from other decryption failures, leading to recovery of the content‑encryption key and thus the plaintext of the original message.

Affected Systems

The vulnerability is present in Legion of the Bouncy Castle Inc. bc‑csharp library, affecting all releases prior to 2.7.0. Consumers of this library that decode CMS EnvelopedData are exposed unless they update to the patched version.

Risk and Exploitability

The CVSS score of 8.2 indicates a high‑severity flaw. No EPSS score is available, but the clear padding oracle and absence of random key injection make exploitation a high‑risk activity. The attack requires that the attacker have a captured message and can send modified ciphertexts to an application that performs CMS decryption, so any service exposing this functionality remotely becomes a target.

Generated by OpenCVE AI on October 2, 2026 at 09:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Legion of the Bouncy Castle Inc. bc‑csharp library to version 2.7.0 or later.
  • If an upgrade is not immediately possible, alter the application to catch CmsException and suppress detailed error messages so that padding errors do not leak to the attacker.
  • Consider replacing CMS RSA PKCS#1 v1.5 key‑transport with OAEP padding or an alternative cryptographic workflow that does not reveal padding status.

Generated by OpenCVE AI on October 2, 2026 at 09:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who holds a captured CMS EnvelopedData message, and who can submit many modified messages to an application that decrypts them with the recipient's RSA private key and reveals how decryption failed, to recover the captured message's content-encryption key and so its content, via a Bleichenbacher-style adaptive chosen-ciphertext attack, because a key-transport ciphertext with invalid PKCS#1 v1.5 padding is rejected during unwrap with a distinct "bad padding in message." CmsException instead of being replaced by a random key, so it can be told apart from a correctly padded ciphertext, which fails only later at content decryption.
Title Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap
Weaknesses CWE-203
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:05:30.227Z

Reserved: 2026-07-16T23:50:45.118Z

Link: CVE-2026-63573

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T08:17:02.317

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:15:08Z

Weaknesses