CVE-2026-16458 PUBLISHED

Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto

Assigner: NCSC.ch
Reserved: 21.07.2026 Published: 13.08.2026 Updated: 13.08.2026

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.9

Product Status

Vendor Oberon microsystems AG
Product ocrypto
Versions Default: unaffected
  • affected from 3.0.0 to 4.0.1 (excl.)

References

Problem Types

  • CWE-208 Observable timing discrepancy CWE
  • CWE-327 CWE

Impacts

  • CAPEC-621 Analysis of Packet Timing and Sizes