GHSA-4j9m-h44m-2hv8
LOWCVE-2026-50268Configuring encrypt:rsa:algorithm=OAEP does not enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the OAEP setting selects PKCS#1 v1.5, which is the same algorithm as the DEFAULT setting.
- Affected
- >= 4.0.0, <= 4.1.0
- Fixed in
- 4.2.0
- Weakness
- CWE-256
- Published
- 2026-07-02
- Source
- github