CMS RSA PKCS#1 v1.5 Key-Transport Vulnerability in Bouncy Castle Library
CVE-2026-63573
8.2HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-63573?
The vulnerability in the CMS RSA PKCS#1 v1.5 key-transport method of the Bouncy Castle library allows an attacker with a captured CMS EnvelopedData message to exploit weaknesses in the decryption process. By submitting modified messages to an application that utilizes the recipient's RSA private key, the attacker can discern how the decryption failed due to specific error messages. This leads to the possibility of recovering the content-encryption key through a Bleichenbacher-style adaptive chosen-ciphertext attack, facilitated by the handling of invalid PKCS#1 v1.5 padding, which reveals whether a ciphertext lacks valid encryption.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
