CVE-2026-12803
published 2026-08-03CVE-2026-12803: In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.17%
6.0th percentile
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| legion_of_the_bouncy_castle_inc | bc-java | < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java/Bouncy Castle for Java LTS prior 1.85/2.73.12 KCCMBlockCipher MAC signature verification (Nessus ID 331790 / WID-SEC-2026-2622)
vuldb·2026-09-03·CVSS 7.5
CVE-2026-12803 [HIGH] Legion of the Bouncy Castle Bouncy Castle for Java/Bouncy Castle for Java LTS prior 1.85/2.73.12 KCCMBlockCipher MAC signature verification (Nessus ID 331790 / WID-SEC-2026-2622)
A vulnerability labeled as problematic has been found in Legion of the Bouncy Castle Bouncy Castle for Java and Bouncy Castle for Java LTS. This affects an unknown part of the component KCCMBlockCipher MAC. Executing a manipulation can lead to improper verification of cryptographic signature.
This vulnerability is handled as CVE-2026-12803. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
GHSA
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
ghsa_unreviewed·2026-08-03
CVE-2026-12803 [HIGH] CWE-354 In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-03
Published