CVE-2024-14041Medium· 5.9▾ SunlitIn Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression r…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
bc-java >= 1.73, < 1.78Upgrade past the affected range:
bc-java 1.78Connected by shared product, vendor, weakness, or advisory.
CVE-2026-14682High· 7.5In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read
CVE-2026-13586High· 7.5In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)
CVE-2026-13506High· 7.5In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard
CVE-2026-59643High· 7.5In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored
CVE-2026-8798HighBouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound
CVE-2026-49265Medium· 6.8Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)