Description
PKCS#1 v1.5 padding for RSA encryption can expose a padding oracle if decryption errors or processing times reveal whether the padding is valid. Unpadded RSA is deterministic and vulnerable to ciphertext manipulation, so it is not a safe alternative.
Potential impact
- Increased risk of ciphertext decryption, message forgery, and disclosure of sensitive information.
Remediation
Use OAEP padding and prefer RSAEncryptionPadding.OaepSHA256 or stronger supported options where possible.
Examples
Before
csharp
return rsa.Encrypt(data, RSAEncryptionPadding.Pkcs1);
After
csharp
return rsa.Encrypt(data, RSAEncryptionPadding.OaepSHA256);
Explanation:
- Before: A padding oracle can arise if the decrypting system distinguishes padding errors when processing PKCS#1 v1.5 ciphertext.
- After: Use OAEP padding, preferring
RSAEncryptionPadding.OaepSHA256or stronger options when supported.