CVE-2026-12802Patch(bouncycastle / bc-java)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch bouncycastle bc-java systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-354

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bc-java
  • bcpkix-fips
  • bouncy_castle_for_java_lts

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
bc-javabcpkix-fipsbouncy_castle_for_java_lts

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-21: 1Patch / Workaround · 2026-06-21: 106-21
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Calif@calif_io
    Patch

    Both Bouncy Castle and GnuPG have acknowledged and fixed the reported issues. CVE-2026-12802 will be published with Bouncy Castle 1.85. GnuPG fix: https://github.com/gpg/gnupg/commit/4c7e68cf3d335328821bdbb70db309a60d0e4fd4

    Post summary

    Both Bouncy Castle and GnuPG have released patches for CVE-2026-12802, with Bouncy Castle 1.85 and a specific commit in GnuPG confirming remediation.

    0603189.8K
    6.6K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appbouncycastlebc-java---
Appbouncycastlebcpkix-fips---
Appbouncycastlebouncy_castle_for_java_lts---

Explore more