Description
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Published: 2026-08-03
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An implementation flaw in the OpenPGP CFB quick‑check logic allows an attacker to observe the oracle responses when processing symmetric or session keys, ultimately revealing confidential key material. The weakness is a form of timing or discrimination oracle, as defined by CWE‑203, and could lead to the decryption of encrypted messages if an attacker can control input to the affected routine. The impact is loss of confidentiality for data protected by the compromised keys.

Affected Systems

The vulnerability affects Bouncy Castle for Java (BC‑JAVA) versions prior to 1.85, the Bouncy Castle for Java LTS (BC‑LTS‑JAVA) versions prior to 2.73.12, and the Bouncy Castle for Java FIPS (BC‑FJA) versions before bcpg‑fips 1.0.13, 2.0.13, and 2.1.13. Systems that rely on these libraries for OpenPGP encryption are at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. The attack requires the ability to influence or observe CFB operations, implying that an attacker with access to the decryption process or who can supply crafted packets could incrementally recover key bits. Given the potential to compromise confidentiality, the risk remains significant until the libraries are updated.

Generated by OpenCVE AI on August 3, 2026 at 09:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Bouncy Castle components to the fixed releases (BC‑JAVA 1.85 or newer, BC‑LTS‑JAVA 2.73.12 or newer, BC‑FJA bcpg‑fips 1.0.13/2.0.13/2.1.13 or newer).
  • If an upgrade cannot be performed immediately, disable the vulnerable OpenPGP CFB quick‑check path or avoid using OpenPGP with symmetric/session keys until a patch is applied.
  • Restrict the execution of OpenPGP processing to trusted users and processes, and monitor for abnormal decryption attempts to reduce exposure while the fix is in place.

Generated by OpenCVE AI on August 3, 2026 at 09:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-fja
Legion Of The Bouncy Castle Inc. bc-java
Legion Of The Bouncy Castle Inc. bc-lts-java
Vendors & Products Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-fja
Legion Of The Bouncy Castle Inc. bc-java
Legion Of The Bouncy Castle Inc. bc-lts-java

Mon, 03 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 05:30:00 +0000


Mon, 03 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Description In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Title OpenPGP CFB quick-check oracle active on symmetric/session-key paths
Weaknesses CWE-203
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber'}


Subscriptions

Legion Of The Bouncy Castle Inc. Bc-fja Bc-java Bc-lts-java
cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-08-03T13:25:07.454Z

Reserved: 2026-07-06T06:58:29.263Z

Link: CVE-2026-59640

cve-icon Vulnrichment

Updated: 2026-08-03T13:25:02.885Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-03T01:16:43.907

Modified: 2026-08-04T14:50:12.360

Link: CVE-2026-59640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:52:24Z

Weaknesses