CVE-2026-16458

Summary

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.

Affected Software

VendorProductVersion RangeStatus
Oberon microsystems AGocrypto3.0.0 < 4.0.1affected

Weaknesses

  • CWE-208: CWE-208 Observable timing discrepancy
  • CWE-327: CWE-327

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References