CVE-2026-63567
Received Received - Intake

Bouncy Castle IES Decryption Padding Oracle Vulnerability

Vulnerability report for CVE-2026-63567, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack, because in block-cipher mode the engine decrypts the ciphertext and removes its padding before verifying the MAC. A padding failure is therefore reported with a different error message, and without the MAC computation, compared with a MAC failure. Only applications that construct IesEngine directly with a padded block cipher, such as AES in CBC mode with PKCS#7 padding, are affected; stream-mode IES is not.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
legion_of_the_bouncy_castle_inc bc-csharp to 2.7.0 (exc)
bouncy_castle bc_csharp 2.6.2
bouncy_castle bc_csharp 2.7.0-beta.98
bouncy_castle bc_csharp 2.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-203 The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a padding-oracle attack in the IesEngine.DecryptBlock function of the Bouncy Castle C# library. It allows a remote attacker who has captured an encrypted message to recover its plaintext by submitting modified ciphertexts for decryption under the same key pair. The issue occurs because the engine decrypts the ciphertext and removes padding before verifying the MAC, leading to different error messages for padding failures versus MAC failures. This discrepancy enables the attacker to exploit the system as a padding oracle.

The vulnerability specifically affects applications that construct IesEngine directly with a padded block cipher like AES in CBC mode with PKCS#7 padding. Stream-mode IES is not affected.

Detection Guidance

This vulnerability is specific to applications using the Bouncy Castle C# library's IesEngine class with block ciphers like AES in CBC mode. Detection requires checking if your application uses IesEngine with BufferedBlockCipher or similar block cipher modes. Review application code for direct IesEngine instantiation with padded block ciphers. No direct network commands detect this; instead, inspect software dependencies and configurations.

Impact Analysis

If you use a vulnerable version of the Bouncy Castle C# library (2.6.2 or earlier, or 2.7.0-beta.98), an attacker could intercept encrypted messages and recover their plaintext without the private key. This could lead to unauthorized access to sensitive data, such as passwords, financial information, or personal communications. The impact is significant for applications handling confidential data.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by exposing sensitive personal or health data. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A breach due to this vulnerability may result in legal penalties, fines, and reputational damage for organizations failing to secure data adequately.

Mitigation Strategies

Upgrade to BC C# .NET version 2.7.0 or later. If upgrading is not possible, avoid using IesEngine with block ciphers like AES-CBC. Instead, use stream-mode IES or ECIES via CipherUtilities. Ensure all decryption failures report uniformly to prevent error-based timing attacks. Manually verify MAC before decrypting and removing padding if using older versions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63567. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart