PT-2026-104559 · Unknown · Bouncy Castle For Java

CVE-2026-71883

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber
Name of the Vulnerable Software and Affected Versions Bouncy Castle for Java LTS versions prior to 2.73.13
Description One-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM, and GCM-SIV incorrectly use JNI's ReleaseByteArrayElements in mode 0 when releasing the caller's key, IV, and additional authenticated data arrays. This mode commits the native copy back into the Java array. In scenarios where an application uses the same Java array for both input and destination—such as encrypting in place over KeyParameter.getKey()—the release of the key overwrites the produced ciphertext with the original unchanged key bytes. Consequently, the application receives the raw AES key instead of the expected ciphertext, which may lead to the key being transmitted or stored in place of the message. Pure-Java packet ciphers, streaming native modes, and Bouncy Castle for Java (bcprov) are not affected.
Recommendations Update Bouncy Castle for Java LTS to version 2.73.13 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71883

Affected Products

Bouncy Castle For Java