CVE-2026-18036
Received Received - Intake

Timing Side Channel in Bouncy Castle Java

Vulnerability report for CVE-2026-18036, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose latency depends on the secret operand. Polynomial.modQ divided by a variable divisor, which a compiler cannot strength-reduce to a multiply the way it can a constant one, so it emitted a division on every call including on the decapsulation path where the dividend derives from the private key; Polynomial.mod3 and NTRUSampling.mod3 divided the secret key polynomials f and g during key generation, the message polynomials r and m during encapsulation, and coefficients recovered during decapsulation. An attacker able to measure that timing can recover information about the NTRU private key. modQ now masks, which is exact because q is always a power of two, and mod3 uses the reference implementation's division-free fold and select; the results are unchanged.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bouncy_castle bouncy_castle to 1.86 (exc)
bcgit bc-java to 1.86 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-208 Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-18036 is a timing side-channel vulnerability in Bouncy Castle for Java before version 1.86. It affects the NTRU post-quantum cryptographic algorithm, where private key information could be leaked due to non-constant-time integer division operations in three helper functions. These functions used the modulo operator (%) to reduce secret values, which compiles to integer division with latency dependent on the secret operand. This creates a timing side channel that could expose private key data during key generation, encapsulation, and decapsulation processes.

Detection Guidance

This vulnerability is specific to the Bouncy Castle Java library before version 1.86. To detect it, check the version of the bc-java library in your system. If you are using a vulnerable version, update to version 1.86 or later immediately. No network-specific commands are required as this is a library-level issue.

Impact Analysis

An attacker with the ability to measure timing differences could exploit this vulnerability to recover information about the NTRU private key. This could lead to the compromise of encrypted communications or data protected by NTRU-based cryptographic operations in applications using Bouncy Castle before version 1.86. The impact is particularly severe if NTRU is used as a first-class algorithm in the application's cryptographic provider.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by potentially exposing private key data through timing side channels during cryptographic operations. Non-constant-time operations in NTRU implementations may allow attackers to recover sensitive information, violating data protection requirements for confidentiality and integrity.

Mitigation Strategies

Immediately upgrade the Bouncy Castle Java library to version 1.86 or later. This version includes fixes for the NTRU modular reduction operations that were vulnerable to timing side-channel attacks. Verify the update by checking the library version in your application dependencies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18036. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart