Side Channel Vulnerability in Bouncy Castle for Java by Bouncy Castle
CVE-2026-18040

5.9MEDIUM

What is CVE-2026-18040?

A vulnerability in Bouncy Castle for Java prior to version 1.86 exposes secret data through side-channel attacks. This occurs due to GF(2^8) arithmetic operations using lookup tables and a fixed-weight support sampler which can reveal sensitive information about the HQC private key. Attackers who can monitor cache behavior or measure time taken during encapsulation and decapsulation processes could potentially exploit this weakness to derive confidential data. The recent fixes have eliminated the use of lookup tables and optimized the sampling process, enhancing security without compromising performance.

Affected Version(s)

BC-JAVA all 1.73 < 1.86

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Robusta team: Deepak Bhargavan Pillai, Anirban Chakraborty, Chitchanok Chuengsatiansup, Matthew Roughan, Peter Schwabe, and Yuval Yarom
.