CVE-2026-71884
Received Received - Intake

Weak CTR Counter Validation in Bouncy Castle for Java LTS

Vulnerability report for CVE-2026-71884, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: bcorg

Description

In Bouncy Castle for Java LTS before 2.73.13, the native one-shot CTR packet cipher did not check that the requested input length fitted the counter space the IV left. In CTR mode the IV and the block counter share one 16-byte block, so an IV of 13 to 15 bytes leaves a counter of only 1 to 3 bytes, addressing 256, 65536 or 16777216 blocks respectively. Given a longer input the counter wrapped and the keystream repeated from the start of the same packet, and the call then returned the full input length as though every byte had been correctly transformed. Two segments of the message were therefore encrypted under the same keystream, so their plaintexts can be recovered from the ciphertext alone, without the key, while the caller saw neither an exception nor a short length to indicate it. The streaming implementation validates at init and again while processing, and the portable AESCTRPacketCipher rejects such a request with "Counter in CTR/SIC mode out of range.", but the native one-shot path has a single entry point and performed no counter-range validation there. It now preflights the IV-derived counter range and rejects an over-long request before any output is written, so the operation is failure-atomic and never reports success for bytes it did not correctly transform. A counter of four bytes or more cannot be exhausted by a Java int length and is unaffected, as is a full 16-byte IV, where the counter range is the caller's responsibility. Bouncy Castle for Java (bcprov) is not affected, as it ships no native implementations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Legion of the Bouncy Castle Inc. BC-LTS-JAVA 2.73.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-323 Nonces should be used for the present occasion and only once.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71884 is a flaw in Bouncy Castle's BC-LTS Java library before version 2.73.13. It affects CTR mode encryption where the IV and block counter share a 16-byte block. If the IV is 13-15 bytes, the counter becomes 1-3 bytes, causing the keystream to repeat when input exceeds the counter limit. The native one-shot path failed to validate this, encrypting data with a repeating keystream and returning success without raising an error.

Detection Guidance

To detect this vulnerability, check the version of Bouncy Castle BC-LTS in use. If you are using a version before 2.73.13 on an Intel platform with native support enabled, the system may be vulnerable. Review encryption operations using CTR mode with IVs of 13 to 15 bytes to see if counter wrapping occurs.

Impact Analysis

An attacker could exploit this to recover plaintext from ciphertext without the encryption key by XORing repeated keystream segments. This compromises confidentiality of encrypted data. The vulnerability only affects systems using BC-LTS with native support on Intel platforms and specific IV lengths.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating confidentiality requirements in GDPR (Article 32) and HIPAA (Security Rule). Organizations using affected versions may face compliance violations, data breach notifications, and potential penalties if encrypted data is compromised.

Mitigation Strategies

Upgrade Bouncy Castle BC-LTS to version 2.73.13 or later. If using native implementations, ensure the counter range is validated before processing. Replace affected native one-shot CTR cipher paths with portable implementations that already include validation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71884. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart