CVE-2026-15999
Received Received - Intake

Improper Integrity Check in Bouncy Castle Crypto Library

Vulnerability report for CVE-2026-15999, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to modify CCM-encrypted content without detection via an AlgorithmIdentifier whose CCMParameters declare an authentication tag (aes-ICVlen) of zero or another length outside the RFC 5084 set, because CcmParameters accepted any value and CcmBlockCipher validated the tag length only when encrypting, so decryption compared a zero-length or very short tag. Affected paths include ParameterUtilities.GetCipherParameters, used by CmsEnvelopedData and CmsEnvelopedDataParser for EnvelopedData encrypted with AES-CCM, and any caller passing an unchecked tag length to CcmBlockCipher for decryption.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bouncy_castle_inc bc_csharp to 2.7.0 (exc)
bouncy_castle_inc bc_csharp 2.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper validation of the authentication tag length in AES-CCM encryption used by Bouncy Castle's C# library. The flaw allows an attacker to modify encrypted content without detection by using an invalid tag length during decryption. The library previously only validated tag lengths during encryption, not decryption, enabling bypass of integrity checks.

Detection Guidance

To detect this vulnerability, check if your system uses Bouncy Castle C# versions 2.6.2 or earlier. Inspect applications using AES-CCM encryption or decryption, particularly those using ParameterUtilities.GetCipherParameters, CmsEnvelopedData, or CmsEnvelopedDataParser. Look for improper tag length validation during decryption processes.

Impact Analysis

If you use Bouncy Castle C# versions 2.6.2 or earlier, an attacker could alter encrypted data without detection. This compromises data integrity, allowing tampering with sensitive information like messages processed by CmsEnvelopedData. Confidentiality remains intact, but integrity is violated.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA, which require integrity and confidentiality of personal and health data. Since integrity is compromised, organizations may fail to meet regulatory requirements for secure data handling and protection.

Mitigation Strategies

Upgrade to Bouncy Castle C# version 2.7.0 or later. If immediate upgrade is not possible, manually verify that AES-CCM tag lengths are within RFC 5084 compliant range (4 to 16 octets in steps of 2) before decryption. Ensure all decryption processes enforce tag length validation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15999. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart