CMS AuthEnvelopedData Vulnerability in Bouncy Castle for Java
CVE-2026-12802

8.7HIGH

What is CVE-2026-12802?

In Bouncy Castle for Java versions prior to 1.85, a vulnerability exists in the CMS AuthEnvelopedData decryption process, which fails to properly enforce tag-length verification. This oversight can pose significant security risks as it may allow unauthorized access to encrypted data. Additionally, the vulnerability affects specific LTS and FIPS versions, necessitating immediate updates to mitigate potential threats.

Affected Version(s)

BC-FJA all 1.0.0 < 1.0.12

BC-FJA all 2.0.0 < 2.0.12

BC-FJA all 2.1.0 < 2.1.12

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thai Duong
.