CVE-2026-63567: IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)

Published Oct 2, 2026
·
Updated

Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack, because in block-cipher mode the engine decrypts the ciphertext and removes its padding before verifying the MAC. A padding failure is therefore reported with a different error message, and without the MAC computation, compared with a MAC failure. Only applications that construct IesEngine directly with a padded block cipher, such as AES in CBC mode with PKCS#7 padding, are affected; stream-mode IES is not.

Affected Software

1 affected component
Bouncy Castle bc-csharp<2.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade bc-csharp to a version that resolves this vulnerability.

    Fixed in 2.7.0

Event History

Oct 2, 2026
CVE Published
via MITRE·06:58 AM
Data Sourced
via MITRE·06:58 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Only applications that directly construct IesEngine with a padded block cipher are affected, such as AES-CBC with PKCS#7 padding. Stream-mode IES is not affected.

2

What does an attacker need to exploit the vulnerability?

The attacker must have captured an IES or ECIES ciphertext and be able to submit modified versions of that ciphertext for decryption using the same key pair. Exploitation relies on observing the different responses for padding failures and MAC failures.

3

How can teams determine whether their application is affected?

Review IesEngine construction and the selected cipher mode. An application is affected if it directly uses IesEngine with a padded block cipher; it is not affected when using stream-mode IES.

4

What is the remediation version?

Upgrade Bouncy Castle bc-csharp to version 2.7.0 or later. Versions before 2.7.0 are affected when used in the vulnerable padded block-cipher configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203