Side Channel Vulnerability in Bouncy Castle for Java by Bouncy Castle
CVE-2026-18040
5.9MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-18040?
A vulnerability in Bouncy Castle for Java prior to version 1.86 exposes secret data through side-channel attacks. This occurs due to GF(2^8) arithmetic operations using lookup tables and a fixed-weight support sampler which can reveal sensitive information about the HQC private key. Attackers who can monitor cache behavior or measure time taken during encapsulation and decapsulation processes could potentially exploit this weakness to derive confidential data. The recent fixes have eliminated the use of lookup tables and optimized the sampling process, enhancing security without compromising performance.
Affected Version(s)
BC-JAVA all 1.73 < 1.86
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The Robusta team: Deepak Bhargavan Pillai, Anirban Chakraborty, Chitchanok Chuengsatiansup, Matthew Roughan, Peter Schwabe, and Yuval Yarom
