CVE-2026-5598HIGHCVSS 0.0

Bouncy Castle Has Covert Timing Channel Vulnerability

Published Apr 17, 2026·Updated Jun 19, 2026

Description

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue only affects users of the FrodoKEM algorithm involved in the decryption of encapsulations. This issue affects BC-JAVA: from 1.71 to 1.80.1, 1.81, 1.82 to 1.83. Fixed versions: 1.80.2, 1.81.1, 1.84

Affected Packages (3)

org.bouncycastle:bcprov-jdk18onMAVEN
From 1.82
Fixed in 1.84
org.bouncycastle:bcprov-jdk14MAVEN
From 1.81
Fixed in 1.81.1
org.bouncycastle:bcprov-jdk15to18MAVEN
From 1.71
Fixed in 1.80.2

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free