CVE-2026-15999: AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication

Published Oct 2, 2026
·
Updated

Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to modify CCM-encrypted content without detection via an AlgorithmIdentifier whose CCMParameters declare an authentication tag (aes-ICVlen) of zero or another length outside the RFC 5084 set, because CcmParameters accepted any value and CcmBlockCipher validated the tag length only when encrypting, so decryption compared a zero-length or very short tag. Affected paths include ParameterUtilities.GetCipherParameters, used by CmsEnvelopedData and CmsEnvelopedDataParser for EnvelopedData encrypted with AES-CCM, and any caller passing an unchecked tag length to CcmBlockCipher for decryption.

Affected Software

1 affected component
Bouncy Castle bc-csharp<2.7.0

Event History

Oct 2, 2026
CVE Published
via MITRE·06:52 AM
Data Sourced
via MITRE·06:52 AM
DescriptionWeakness

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications using bc-csharp before 2.7.0 to decrypt AES-CCM data are affected when the CCM authentication-tag length comes from an untrusted or unchecked source. This includes CMS EnvelopedData processing through CmsEnvelopedData or CmsEnvelopedDataParser, as well as direct CcmBlockCipher decryption callers that pass an unchecked tag length.

2

What does an attacker need to exploit the flaw?

An attacker needs to be on path and able to modify AES-CCM-encrypted content, including supplying an AlgorithmIdentifier whose CCMParameters declares a zero-length or otherwise invalid authentication tag length. The vulnerable decryption path can then compare a zero-length or very short tag and fail to detect modification.

3

Are all AES-CCM uses affected by default?

The issue is specifically triggered when decryption accepts an AlgorithmIdentifier or caller-supplied tag length that is zero or outside the RFC 5084 set. Encryption validated tag lengths, but the affected decryption handling did not.

4

What can be done before upgrading?

Do not accept unchecked CCM tag lengths for decryption. Reject zero-length tags and tag lengths outside the RFC 5084 set before passing parameters to CcmBlockCipher or processing CMS EnvelopedData.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203