---
id: CVE-2024-14041
title: >-
  In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM
  (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by
  the modulus q: Poly.toMsg, which decodes the decrypted message, and the
  ciphertext compression r…
summary: >-
  In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM
  (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by
  the modulus q: Poly.toMsg, which decodes the decrypted message, and the
  ciphertext compression r…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-208
vendor: bouncycastle
product: bc-java
affected:
  - 'bc-java >= 1.73, < 1.78'
patched:
  - bc-java 1.78
published: '2026-07-28'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:10:00.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-14041'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/1590247178f2280defa36421475f015175dfbe9e
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://github.com/bcgit/bc-java/commit/5adb2c5c5b462a332b01a012bea0784b40b904e5
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE-2024-14041'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://kyberslash.cr.yp.to/'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
tags:
  - nvd
epss: 0.00345
epssPercentile: 0.25595
ingestedAt: '2026-10-02T01:05:54.734Z'
---

## Overview

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.

## Affected

- `bc-java >= 1.73, < 1.78`

## Remediation

Upgrade past the affected range:

- `bc-java 1.78`
