CVE-2026-63567: IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)
Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack, because in block-cipher mode the engine decrypts the ciphertext and removes its padding before verifying the MAC. A padding failure is therefore reported with a different error message, and without the MAC computation, compared with a MAC failure. Only applications that construct IesEngine directly with a padded block cipher, such as AES in CBC mode with PKCS#7 padding, are affected; stream-mode IES is not.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
bc-csharpto a version that resolves this vulnerability.Fixed in 2.7.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Only applications that directly construct IesEngine with a padded block cipher are affected, such as AES-CBC with PKCS#7 padding. Stream-mode IES is not affected.
What does an attacker need to exploit the vulnerability?
The attacker must have captured an IES or ECIES ciphertext and be able to submit modified versions of that ciphertext for decryption using the same key pair. Exploitation relies on observing the different responses for padding failures and MAC failures.
How can teams determine whether their application is affected?
Review IesEngine construction and the selected cipher mode. An application is affected if it directly uses IesEngine with a padded block cipher; it is not affected when using stream-mode IES.
What is the remediation version?
Upgrade Bouncy Castle bc-csharp to version 2.7.0 or later. Versions before 2.7.0 are affected when used in the vulnerable padded block-cipher configuration.