Skip to content

CVE-2026-5598: org.bouncycastle:bcprov-jdk18on:jar:1.78.1:compile #389

Description

@github-actions

Summary

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules).
Non-constant time comparisons risk private key leakage in FrodoKEM.

This issue affects BC-JAVA: from 2.17.3 before 1.84.

CVE: CVE-2026-5598
CWE: CWE-385

References

Metadata

Metadata

Assignees

Labels

securitySecurity related change

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions