CMS AuthEnvelopedData Vulnerability in Bouncy Castle for Java
CVE-2026-12802
8.7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2026-12802?
In Bouncy Castle for Java versions prior to 1.85, a vulnerability exists in the CMS AuthEnvelopedData decryption process, which fails to properly enforce tag-length verification. This oversight can pose significant security risks as it may allow unauthorized access to encrypted data. Additionally, the vulnerability affects specific LTS and FIPS versions, necessitating immediate updates to mitigate potential threats.
Affected Version(s)
BC-FJA all 1.0.0 < 1.0.12
BC-FJA all 2.0.0 < 2.0.12
BC-FJA all 2.1.0 < 2.1.12
