CVE-2026-12802
published 2026-08-03CVE-2026-12802: In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.15%
4.2th percentile
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bcpkix-fips | < 1.0.12 | 1.0.12 |
| bouncycastle | bcpkix-fips | >= 2.0.7 < 2.0.12 | 2.0.12 |
| bouncycastle | bcpkix-fips | >= 2.1.8 < 2.1.12 | 2.1.12 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| jboss-eap-7 | eap74-els-openjdk11-openshift-rhel8 | — | — |
| jboss-eap-7 | eap74-els-openjdk17-openshift-rhel8 | — | — |
| jboss-eap-7 | eap74-els-openjdk8-openshift-rhel8 | — | — |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.0 < 1.0.12 | 1.0.12 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.12 | 2.0.12 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.12 | 2.1.12 |
| legion_of_the_bouncy_castle_inc | bc-java | < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java AuthEnvelopedData signature verification (WID-SEC-2026-2622)
vuldb·2026-09-03·CVSS 7.5
CVE-2026-12802 [HIGH] Legion of the Bouncy Castle Bouncy Castle for Java AuthEnvelopedData signature verification (WID-SEC-2026-2622)
A vulnerability identified as critical has been detected in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS. Affected by this issue is some unknown functionality of the component AuthEnvelopedData. Performing a manipulation results in improper verification of cryptographic signature.
This vulnerability is known as CVE-2026-12802. Remote exploitation of the attack is possible. No exploit is available.
GHSA
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption.
ghsa_unreviewed·2026-08-03
CVE-2026-12802 [HIGH] CWE-354 In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption.
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Red Hat
bouncycastle: bcpkix-fips: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption.
vendor_redhat·2026-08-03·CVSS 8.7
CVE-2026-12802 [HIGH] CWE-347 bouncycastle: bcpkix-fips: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption.
bouncycastle: bcpkix-fips: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption.
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
A flaw was found in Bouncy Castle for Java. This vulnerability allows a remote attacker to compromise the integrity of data during the decryption of Cryptographic Message Syntax (CMS) AuthEnvelopedData. The software fails to properly enforce the tag-length, which could enable an attacker to manipulate encrypted data without detection.
State
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-12802 bouncycastle: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption. [epel-all]
bugzilla·2026-08-27·CVSS 8.7
CVE-2026-12802 [HIGH] CVE-2026-12802 bouncycastle: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption. [epel-all]
CVE-2026-12802 bouncycastle: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption. [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Bugzilla
CVE-2026-12802 bouncycastle: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption. [fedora-all]
bugzilla·2026-08-27·CVSS 8.7
CVE-2026-12802 [HIGH] CVE-2026-12802 bouncycastle: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption. [fedora-all]
CVE-2026-12802 bouncycastle: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Bugzilla
CVE-2026-12802 bouncycastle: bcpkix-fips: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption.
bugzilla·2026-08-03·CVSS 8.7
CVE-2026-12802 [HIGH] CVE-2026-12802 bouncycastle: bcpkix-fips: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption.
CVE-2026-12802 bouncycastle: bcpkix-fips: Bouncy Castle for Java: Integrity compromise due to insufficient tag-length enforcement in CMS AuthEnvelopedData decryption.
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
2026-08-03
Published