CVE-2026-16001
Received Received - Intake

Exposure of MAC Key via Encryption Keystream in Bouncy Castle IesEngine

Vulnerability report for CVE-2026-16001, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed without a block cipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has observed one encrypted message with known plaintext to forge shorter messages of their choosing that the recipient accepts as authentic, via a crafted ciphertext and MAC tag, because the MAC key was taken from the key derivation output directly after a keystream as long as the message, while the derivation input depends only on the static key pair and fixed parameters. The keystream revealed by that one message therefore contains the MAC key for every sufficiently shorter message.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
bouncy_castle bc-csharp to 2.7.0 (exc)
bouncy_castle bc_csharp to 2.7.0 (exc)
bouncy_castle bc_csharp to 2.7.0-beta.98 (inc)
bouncy_castle bc_java 1.85

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the IesEngine class in Bouncy Castle C# versions 2.6.2 and earlier. When IesEngine operates in stream mode without a block cipher, messages are encrypted by XORing with a keystream derived from a key derivation function (KDF). The MAC key is taken from the KDF output immediately after the keystream. Since the KDF input is static for the same key pair, every message uses the same KDF output. An attacker who observes one encrypted message with known plaintext can recover the keystream, which includes MAC keys for shorter messages. This allows forging shorter messages with arbitrary content that the recipient accepts as authentic without needing private keys.

Detection Guidance

To detect this vulnerability, check if your system uses Bouncy Castle C# .NET versions 2.6.2 or earlier, or 2.7.0-beta.98 pre-release. Inspect applications using IesEngine in stream mode with DH or EC Diffie-Hellman. Verify if messages are encrypted without block cipher mode. Commands: grep -r "IesEngine" /path/to/codebase, dotnet list package | grep BouncyCastle, or check version in package.json.

Impact Analysis

An attacker could forge shorter encrypted messages that appear authentic to the recipient, even without access to private keys. This could lead to unauthorized data manipulation or injection of malicious content. Applications using IesEngine in stream mode with DH or EC Diffie-Hellman are at risk. Upgrading to version 2.7.0 may break compatibility with messages encrypted in earlier versions.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by compromising message authentication and integrity. GDPR requires data integrity and confidentiality (Article 32), while HIPAA mandates secure transmission of protected health information (45 CFR Β§ 164.312). The flaw allows attackers to forge messages without access to private keys, potentially violating integrity requirements and exposing sensitive data.

Mitigation Strategies

Upgrade to Bouncy Castle C# .NET version 2.7.0 or later to address the vulnerability in IesEngine stream mode. Avoid using stream mode for confidential data and switch to block-cipher mode instead. Note that upgrading will make messages encrypted in stream mode by earlier versions undecryptable.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16001. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart