PT-2026-67011 · Legion Of The Bouncy Castle · Bc-Java+1

CVE-2026-12185

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12185

Affected Products

Bc-Java
Bc-Lts-Java