Vulnerability in Bouncy Castle for Java LTS Affects Data Security
CVE-2026-71883

8.2HIGH

What is CVE-2026-71883?

A vulnerability in Bouncy Castle for Java LTS prior to version 2.73.13 allows an attacker to inadvertently expose encryption keys. This occurs due to the improper handling of native packet ciphers during the encryption process. When an application uses the same Java array for both input and output during encryption, the encryption key can be overwritten and exposed instead of producing the expected ciphertext. This crucial security flaw can lead to significant data breaches if exploited, as sensitive keys may be transmitted or stored in place of the actual encrypted message. Users should upgrade to the latest version to mitigate these risks.

Affected Version(s)

BC-LTS-JAVA x86 2.73.4 < 2.73.13

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.