CVE-2026-71883
Received Received - Intake

Memory Corruption in Bouncy Castle for Java LTS

Vulnerability report for CVE-2026-71883, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: bcorg

Description

In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM and GCM-SIV released the caller's key, IV and additional authenticated data arrays with JNI's ReleaseByteArrayElements in mode 0, which commits the native copy back into the Java array. Those arrays are read-only to the native code, and on a JVM that returns a copy rather than a pin the copy still holds the input bytes as they were read. The output buffer is taken through a separate critical region and committed first, so where an application passed the same Java array as both an input and the destination - encrypting in place over KeyParameter.getKey(), for example - the later mode-0 release of the key wrote the unchanged key bytes over the ciphertext that had just been produced. The call still returned the correct output length, so an application encrypting in place over its own key array was handed the raw AES key where it expected ciphertext, with nothing in the API to indicate it, and would transmit or store the key in place of the message. The read-only input arrays are now released with JNI_ABORT, freeing the native copy without copying it back, and mode 0 is reserved for arrays the native code wrote. The pure-Java packet ciphers and the streaming native modes are not affected. Bouncy Castle for Java (bcprov) is not affected, as it ships no native implementations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bouncy_castle bc_lts to 2.73.13 (exc)
bcprov bouncy_castle to 2.73.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71883 is a vulnerability in Bouncy Castle for Java LTS before 2.73.13 where native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM and GCM-SIV release caller's key, IV and additional authenticated data arrays with JNI's ReleaseByteArrayElements in mode 0. This causes the raw AES key to overwrite ciphertext when the same Java array is used for input and output during in-place encryption.

Detection Guidance

Check if your system uses Bouncy Castle LTS versions before 2.73.13 with native AES packet cipher support enabled. Inspect Java applications for in-place encryption where the same array is used for both input and output with KeyParameter.getKey(). Use commands like 'java -version' to check Bouncy Castle version and 'jcmd <pid> VM.native_memory' to inspect native memory usage.

Impact Analysis

If exploited, this vulnerability could cause applications to transmit or store the raw AES key instead of ciphertext, potentially exposing sensitive encryption keys. This happens when an application encrypts in place over its own key array.

Compliance Impact

This vulnerability could lead to unauthorized exposure of cryptographic keys if an application encrypts in place over its own key array. This may violate data protection requirements under GDPR (e.g., Article 32 on encryption) and HIPAA (e.g., Security Rule on encryption of PHI) by failing to properly protect sensitive data, as keys could be transmitted or stored in place of ciphertext.

Mitigation Strategies

Upgrade Bouncy Castle LTS to version 2.73.13 or later. Disable native AES packet cipher support if not required. Review Java applications for in-place encryption patterns and modify them to avoid using the same array for input and output with keys.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71883. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart