PT-2026-71405 · Crypto++ · Crypto++
CVE-2026-16458
·
Published
2026-08-13
·
Updated
2026-08-13
CVSS v4.0
5.9
Medium
| Vector | AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ocrypto versions 3.0.0 through 4.0.0
Description
A padding oracle attack exists in the ocrypto library. This issue allows an attacker to recover plaintexts by performing timing measurements of RSA PKCS#1 v1.5 decrypt operations. A padding oracle attack is a side-channel attack where an attacker can decrypt data by observing the errors or timing differences produced by the system when processing encrypted data with incorrect padding.
Recommendations
Update ocrypto to version 4.0.1.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crypto++