Cryptographic Vulnerability in Bouncy Castle C# Implementation by Legion of the Bouncy Castle Inc.
CVE-2026-16000

8.7HIGH

What is CVE-2026-16000?

The vulnerability stems from a missing cryptographic step in the DSTU 7624 CCM mode implementation within the bc-csharp library. This flaw allows an attacker, who can monitor encrypted messages with known or chosen content, to create forged ciphertexts that carry valid authentication tags. The issue arises specifically when messages are encrypted without associated data; in this scenario, the system generates a tag that is a CBC-MAC of the plaintext only, devoid of nonce dependence. This leaves applications utilizing the KCcmBlockCipher without associated data directly exposed to attacks, highlighting the critical importance of properly implementing associated data in encryption protocols.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.