Timing Attack Vulnerability in Bouncy Castle for Java by BC
CVE-2026-18036

8.2HIGH

What is CVE-2026-18036?

Bouncy Castle for Java prior to version 1.86 is susceptible to a timing attack due to the use of the division operator on secret values in its NTRU implementation. This flaw allows attackers to exploit the varying latency of integer division when accessing private key information, potentially leading to the recovery of the NTRU private key. The polynomial modulus operations employed during key generation and encapsulation reveal critical timing information that attackers can leverage. This vulnerability has been addressed in the latest versions by applying modifications to mask operations, significantly reducing the risk of private key exposure.

Affected Version(s)

BC-JAVA all 1.73 < 1.86

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Robusta team: Deepak Bhargavan Pillai, Anirban Chakraborty, Chitchanok Chuengsatiansup, Matthew Roughan, Peter Schwabe, and Yuval Yarom
.