CVE-2026-16459

Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.

Scoring

Severity
MEDIUM
CVSS base score
5.9
CVSS vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS probability
0.07%
CWE
CWE-208, CWE-327
Published
2026-08-13
Last modified
2026-08-13

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs