ENS DNSSEC Oracle Vulnerable to RSA Signature Forgery via Missing PKCS#1 v1.5 Padding Validation
Low severity
GitHub Reviewed
Published
Feb 25, 2026
in
ensdomains/ens-contracts
•
Updated Feb 27, 2026
Description
Published by the National Vulnerability Database
Feb 25, 2026
Published to the GitHub Advisory Database
Feb 25, 2026
Reviewed
Feb 25, 2026
Last updated
Feb 27, 2026
Impact
The
RSASHA256AlgorithmandRSASHA1Algorithmcontracts fail to validate PKCS#1 v1.5 padding structure when verifying RSA signatures. The contracts only check if the last 32 (or 20) bytes of the decrypted signature match the expected hash. This enables Bleichenbacher's 2006 signature forgery attack against DNS zones using RSA keys with low public exponents (e=3). Two ENS-supported TLDs (.cc and .name) use e=3 for their Key Signing Keys, allowing any domain under these TLDs to be fraudulently claimed on ENS without DNS ownership.Affected contracts
Patches
The bug was reported via Immunefi with possible solutions. The patch was merged at ensdomains/ens-contracts@c76c5ad
Workarounds
Resources
https://github.com/ensdomains/ens-contracts-bug-62248-pr-509
References