Padding Oracle Attack in Oberon Microsystem AG’s Ocrypto Library
CVE-2026-16458
5.9MEDIUM
What is CVE-2026-16458?
A vulnerability has been identified in the Ocrypto library developed by Oberon microsystem AG, which affects all versions from 3.0.0 to prior 4.0.1. This issue arises from a padding oracle attack that enables an unauthorized actor to potentially recover plaintexts by analyzing timing variations of RSA PKCS#1 v1.5 decryption operations. As a result, systems utilizing this library may be at risk of data exposure, highlighting the importance of immediate updates and monitoring.
Affected Version(s)
ocrypto 3.0.0 < 4.0.1
