🔐 CVE Alert

CVE-2026-16458

UNKNOWN 0.0

Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.

CWE CWE-208 CWE-327
Vendor oberon microsystems ag
Product ocrypto
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for oberon microsystems ag ocrypto

Be the first to know when new unknown vulnerabilities affecting oberon microsystems ag ocrypto are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Oberon microsystems AG / ocrypto
3.0.0 < 4.0.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
oberon.ch: https://www.oberon.ch/security-advisories/cve-2026-16458/