CVE-2026-63573
Received Received - Intake

Bleichenbacher Attack on Bouncy Castle CMS Unwrap

Vulnerability report for CVE-2026-63573, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who holds a captured CMS EnvelopedData message, and who can submit many modified messages to an application that decrypts them with the recipient's RSA private key and reveals how decryption failed, to recover the captured message's content-encryption key and so its content, via a Bleichenbacher-style adaptive chosen-ciphertext attack, because a key-transport ciphertext with invalid PKCS#1 v1.5 padding is rejected during unwrap with a distinct "bad padding in message." CmsException instead of being replaced by a random key, so it can be told apart from a correctly padded ciphertext, which fails only later at content decryption.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
legion_of_the_bouncy_castle_inc bc-csharp to 2.7.0 (exc)
legion_of_the_bouncy_castle_inc bc_csharp to 2.7.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-203 The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a padding oracle attack on RSA PKCS#1 v1.5 key transport in CMS EnvelopedData and AuthenticatedData decryption. The Bouncy Castle library versions before 2.7.0 would immediately reject invalid PKCS#1 v1.5 padding with a specific error message, allowing attackers to distinguish between valid and invalid padding through error messages or timing. This creates a Bleichenbacher-style padding oracle, enabling decryption of captured messages by submitting modified ciphertexts.

Detection Guidance

Detecting this vulnerability requires checking if your system uses vulnerable versions of Bouncy Castle C# library (2.6.2 or earlier). Inspect installed packages for bc-csharp and verify version numbers. Monitor application logs for RSA PKCS#1 v1.5 decryption failures or timing discrepancies during CMS decryption operations.

Impact Analysis

An attacker who captures an encrypted message and can submit many modified versions of it to a system decrypting with your RSA private key could recover the original message's content. This could lead to unauthorized access to sensitive data, such as encrypted emails, files, or other confidential information protected by the vulnerable library.

Compliance Impact

This vulnerability could lead to unauthorized decryption of sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected versions of the Bouncy Castle library may fail to protect personal or health data adequately, risking non-compliance with data protection regulations and potential legal consequences.

Mitigation Strategies

Upgrade to BC C# .NET 2.7.0 or later immediately. If upgrading is not possible, set the 'Org.BouncyCastle.Cms.AllowLenientRsaPkcs1' property to false to enforce constant-time unwrapping. Alternatively, reject RSA PKCS#1 v1.5 recipients before decryption or ensure all decryption failures are handled uniformly to prevent timing leaks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63573. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart