Padding Oracle Vulnerability in Bouncy Castle's IesEngine Module
CVE-2026-63567

8.2HIGH

What is CVE-2026-63567?

A vulnerability in the IesEngine.DecryptBlock component of the Bouncy Castle library exposes applications to a padding oracle attack. This occurs when a remote attacker captures a ciphertext, modifies it, and submits it for decryption under the same key. The flaw lies in block-cipher mode where decryption occurs, and padding is removed before MAC verification. This allows the attacker to discern differences in error messages between padding and MAC failures, potentially leading to plaintext recovery. Applications directly utilizing IesEngine with a padded block cipher, such as AES in CBC mode with PKCS#7 padding, are particularly susceptible, while stream-mode IES remains unaffected.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.