CVE-2026-16458
Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
| CWE | CWE-208 CWE-327 |
| Vendor | oberon microsystems ag |
| Product | ocrypto |
| Published | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for oberon microsystems ag ocrypto
Be the first to know when new unknown vulnerabilities affecting oberon microsystems ag ocrypto are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Oberon microsystems AG / ocrypto
3.0.0 < 4.0.1