BC-JAVA vulnerability

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

Published 15 Apr 2026Updated 10 Sep 202613 sources
CVSS 8.9

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.