CVE-2026-63573: CWE-203 Observable Discrepancy in Legion of the Bouncy Castle Inc. bc-csharp
Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who holds a captured CMS EnvelopedData message, and who can submit many modified messages to an application that decrypts them with the recipient's RSA private key and reveals how decryption failed, to recover the captured message's content-encryption key and so its content, via a Bleichenbacher-style adaptive chosen-ciphertext attack, because a key-transport ciphertext with invalid PKCS#1 v1.5 padding is rejected during unwrap with a distinct "bad padding in message." CmsException instead of being replaced by a random key, so it can be told apart from a correctly padded ciphertext, which fails only later at content decryption.
AI Analysis
Technical Summary
The vulnerability arises from the KeyTransRecipientInformation.UnwrapKey method in bc-csharp versions before 2.7.0. When decrypting CMS EnvelopedData messages using RSA PKCS#1 v1.5 padding, the library rejects ciphertexts with invalid padding by throwing a distinct "bad padding in message." CmsException instead of replacing the key with a random value. This discrepancy allows a remote attacker, who can submit many modified ciphertexts and observe decryption error differences, to recover the content-encryption key via a Bleichenbacher-style adaptive chosen-ciphertext attack.
Potential Impact
An unauthenticated remote attacker who has captured a CMS EnvelopedData message can exploit this vulnerability to recover the content-encryption key and thus decrypt the protected content. This compromises the confidentiality of the encrypted data. The attack requires the ability to submit many modified ciphertexts to the decryption application and observe distinct error responses.
Mitigation Recommendations
A fixed version 2.7.0 of bc-csharp is available that addresses this vulnerability. Users should upgrade to version 2.7.0 or later to remediate the issue. No other mitigation guidance is provided, and no indication exists that the vulnerability is mitigated without applying the fix.
CVE-2026-63573: CWE-203 Observable Discrepancy in Legion of the Bouncy Castle Inc. bc-csharp
Description
Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who holds a captured CMS EnvelopedData message, and who can submit many modified messages to an application that decrypts them with the recipient's RSA private key and reveals how decryption failed, to recover the captured message's content-encryption key and so its content, via a Bleichenbacher-style adaptive chosen-ciphertext attack, because a key-transport ciphertext with invalid PKCS#1 v1.5 padding is rejected during unwrap with a distinct "bad padding in message." CmsException instead of being replaced by a random key, so it can be told apart from a correctly padded ciphertext, which fails only later at content decryption.
CVSS v4.0
Score 8.2high
Affected software
Legion of the Bouncy Castle Inc.
bc-csharp
pkg:nuget/BouncyCastle.CryptographyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from the KeyTransRecipientInformation.UnwrapKey method in bc-csharp versions before 2.7.0. When decrypting CMS EnvelopedData messages using RSA PKCS#1 v1.5 padding, the library rejects ciphertexts with invalid padding by throwing a distinct "bad padding in message." CmsException instead of replacing the key with a random value. This discrepancy allows a remote attacker, who can submit many modified ciphertexts and observe decryption error differences, to recover the content-encryption key via a Bleichenbacher-style adaptive chosen-ciphertext attack.
Potential Impact
An unauthenticated remote attacker who has captured a CMS EnvelopedData message can exploit this vulnerability to recover the content-encryption key and thus decrypt the protected content. This compromises the confidentiality of the encrypted data. The attack requires the ability to submit many modified ciphertexts to the decryption application and observe distinct error responses.
Mitigation Recommendations
A fixed version 2.7.0 of bc-csharp is available that addresses this vulnerability. Users should upgrade to version 2.7.0 or later to remediate the issue. No other mitigation guidance is provided, and no indication exists that the vulnerability is mitigated without applying the fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- bcorg
- Date Reserved
- 2026-07-16T23:50:45.118Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abf5de5a43b0b3b8988e87c
Added to database: 10/02/2026, 07:31:49 UTC
Last enriched: 10/02/2026, 07:46:26 UTC
Last updated: 10/04/2026, 03:45:56 UTC
Views: 31
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.