CVE-2026-63567
Published:October 02, 2026
Updated:October 09, 2026
Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack, because in block-cipher mode the engine decrypts the ciphertext and removes its padding before verifying the MAC. A padding failure is therefore reported with a different error message, and without the MAC computation, compared with a MAC failure. Only applications that construct IesEngine directly with a padded block cipher, such as AES in CBC mode with PKCS#7 padding, are affected; stream-mode IES is not.
Affected Packages
BouncyCastle.Cryptography (DOT_NET):
Affected version(s) >=2.0.0.20352 <2.7.0Fix Suggestion:
Update to version 2.7.0https://github.com/bcgit/bc-csharp.git (GITHUB):
Affected version(s) >=release-2.0.0 <release-2.7.0Fix Suggestion:
Update to version release-2.7.0bouncycastle.cryptography (NUGET):
Affected version(s) >=2.0.0 <2.7.0Fix Suggestion:
Update to version 2.7.0Related Resources (7)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.2
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE
Weakness Type (CWE)
Observable Discrepancy
EPSS
Base Score:
0.47