10
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules).
Non-constant time comparisons risk private key leakage in FrodoKEM.
This issue affects BC-JAVA: from 2.17.3 before 1.84.
Non-constant time comparisons risk private key leakage in FrodoKEM.
This issue affects BC-JAVA: from 2.17.3 before 1.84.
AI Analysis
Non-constant time comparisons risk private key leakage in FrodoKEM due to a covert timing channel vulnerability in the BC-JAVA core.
Basic Information
ID
CVE-2026-5598
Source
bcorg
Published
Apr 15, 2026 at 09:05
Affected Product
Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
Version
2.17.3
Affected Versions
Legion of the Bouncy Castle Inc. BC-JAVA 2.17.3
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
Version
2.17.3