
Both Bouncy Castle and GnuPG have acknowledged and fixed the reported issues. CVE-2026-12802 will be published with Bouncy Castle 1.85. GnuPG fix: https://github.com/gpg/gnupg/commit/4c7e68cf3d335328821bdbb70db309a60d0e4fd4
Post summary
Both Bouncy Castle and GnuPG have released patches for CVE-2026-12802, with Bouncy Castle 1.85 and a specific commit in GnuPG confirming remediation.
