PT-2026-71405 · Crypto++ · Crypto++

CVE-2026-16458

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v4.0

5.9

Medium

VectorAV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ocrypto versions 3.0.0 through 4.0.0
Description A padding oracle attack exists in the ocrypto library. This issue allows an attacker to recover plaintexts by performing timing measurements of RSA PKCS#1 v1.5 decrypt operations. A padding oracle attack is a side-channel attack where an attacker can decrypt data by observing the errors or timing differences produced by the system when processing encrypted data with incorrect padding.
Recommendations Update ocrypto to version 4.0.1.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16458

Affected Products

Crypto++