---
id: CVE-2026-63573
title: >-
  Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap
  (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc
summary: >-
  Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap
  (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc.
  bc-csharp before 2.7.0 allows a remote attacker who holds a captured CMS
  EnvelopedData me…
severity: high
cvss: 8.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-203
vendor: Legion of the Bouncy Castle Inc.
product: BouncyCastle.Cryptography
affected:
  - BouncyCastle.Cryptography < 2.7.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T08:17:02.317'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63573'
references:
  - url: >-
      https://github.com/bcgit/bc-csharp/commit/85679cc7023adf4e2a0650b88a1f4f98679c7463
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://github.com/bcgit/bc-csharp/commit/c38b4790e2aef68f116a551f73b94ea05cb5590c
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63573'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T08:14:06.228Z'
---

## Overview

Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who holds a captured CMS EnvelopedData message, and who can submit many modified messages to an application that decrypts them with the recipient's RSA private key and reveals how decryption failed, to recover the captured message's content-encryption key and so its content, via a Bleichenbacher-style adaptive chosen-ciphertext attack, because a key-transport ciphertext with invalid PKCS#1 v1.5 padding is rejected during unwrap with a distinct "bad padding in message." CmsException instead of being replaced by a random key, so it can be told apart from a correctly padded ciphertext, which fails only later at content decryption.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
