Padding Oracle Vulnerability in Bouncy Castle's IesEngine Module
CVE-2026-63567
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-63567?
A vulnerability in the IesEngine.DecryptBlock component of the Bouncy Castle library exposes applications to a padding oracle attack. This occurs when a remote attacker captures a ciphertext, modifies it, and submits it for decryption under the same key. The flaw lies in block-cipher mode where decryption occurs, and padding is removed before MAC verification. This allows the attacker to discern differences in error messages between padding and MAC failures, potentially leading to plaintext recovery. Applications directly utilizing IesEngine with a padded block cipher, such as AES in CBC mode with PKCS#7 padding, are particularly susceptible, while stream-mode IES remains unaffected.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
