CVE-2024-14041
published 2026-07-28CVE-2024-14041: In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q…
PriorityP333medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.34%
27.4th percentile
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | >= 1.73 < 1.78 | 1.78 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.73 < 1.78 | 1.78 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.2HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Legion of the Bouncy Castle BC-JAVA up to 1.77 ML-KEM timing discrepancy (EUVD-2024-55702)
vuldb·2026-08-10·CVSS 8.2
CVE-2024-14041 [HIGH] Legion of the Bouncy Castle BC-JAVA up to 1.77 ML-KEM timing discrepancy (EUVD-2024-55702)
A vulnerability classified as problematic has been found in Legion of the Bouncy Castle BC-JAVA up to 1.77. This affects the function Poly.toMsg/Poly.compressPoly/PolyVec.compressPolyVec of the component ML-KEM. This manipulation causes observable timing discrepancy.
The identification of this vulnerability is CVE-2024-14041. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted mess
ghsa_unreviewed·2026-07-28
CVE-2024-14041 [HIGH] CWE-208 In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted mess
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
Red Hat
bouncycastle: Bouncy Castle for Java: Private key recovery via timing side-channel in ML-KEM (CRYSTALS-Kyber) routines
vendor_redhat·2026-07-28·CVSS 8.2
CVE-2024-14041 [HIGH] CWE-208 bouncycastle: Bouncy Castle for Java: Private key recovery via timing side-channel in ML-KEM (CRYSTALS-Kyber) routines
bouncycastle: Bouncy Castle for Java: Private key recovery via timing side-channel in ML-KEM (CRYSTALS-Kyber) routines
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
A flaw was found in Bouncy Castle fo
No detection rules found.
No public exploits indexed.
2026-07-28
Published