In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-03 04:16
Updated : 2026-09-02 14:37
NVD link : CVE-2026-12803
Mitre link : CVE-2026-12803
CVE.ORG link : CVE-2026-12803
JSON object : View
Products Affected
bouncycastle
- bouncy_castle_for_java_lts
- bc-java
CWE
CWE-354
Improper Validation of Integrity Check Value
