PT-2026-104559 · Unknown · Bouncy Castle For Java
CVE-2026-71883
·
Published
2026-10-03
·
Updated
2026-10-03
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber |
Name of the Vulnerable Software and Affected Versions
Bouncy Castle for Java LTS versions prior to 2.73.13
Description
One-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM, and GCM-SIV incorrectly use JNI's
ReleaseByteArrayElements in mode 0 when releasing the caller's key, IV, and additional authenticated data arrays. This mode commits the native copy back into the Java array. In scenarios where an application uses the same Java array for both input and destination—such as encrypting in place over KeyParameter.getKey()—the release of the key overwrites the produced ciphertext with the original unchanged key bytes. Consequently, the application receives the raw AES key instead of the expected ciphertext, which may lead to the key being transmitted or stored in place of the message. Pure-Java packet ciphers, streaming native modes, and Bouncy Castle for Java (bcprov) are not affected.Recommendations
Update Bouncy Castle for Java LTS to version 2.73.13 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bouncy Castle For Java