This issue affects BC-JAVA: from 1.71 before 1.84.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p93r-85wp-75v3 | Bouncy Castle Has Covert Timing Channel Vulnerability |
Tue, 21 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). Non-constant time comparisons risk private key leakage in FrodoKEM. This issue affects BC-JAVA: from 2.17.3 before 1.84. | Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.84. |
| References |
| |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Sat, 18 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 15 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bouncycastle
Bouncycastle bc-java |
|
| Vendors & Products |
Bouncycastle
Bouncycastle bc-java |
Wed, 15 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). Non-constant time comparisons risk private key leakage in FrodoKEM. This issue affects BC-JAVA: from 2.17.3 before 1.84. | |
| Title | Non-constant time comparisons risk private key leakage in FrodoKEM. | |
| Weaknesses | CWE-385 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: bcorg
Published:
Updated: 2026-04-22T11:14:16.581Z
Reserved: 2026-04-05T07:25:44.930Z
Link: CVE-2026-5598
Updated: 2026-04-15T13:11:50.359Z
Status : Awaiting Analysis
Published: 2026-04-15T10:16:49.757
Modified: 2026-04-21T16:16:20.717
Link: CVE-2026-5598
OpenCVE Enrichment
Updated: 2026-04-21T23:30:02Z
Github GHSA