Description
In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Severity (CVSS)
| Base score | 7.1 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber |
| Provided by | CNA |
Weaknesses
- CWE-326 — CWE-326 Inadequate Encryption Strength
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 0 to <1.85 |
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 to <2.73.12 |
References
Generated from the official CVE List on 03 Aug 2026 08:53 UTC.