CVE-2026-5598

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.80.1, from 1.82 before 1.84.

Credits

Cristina Dueñas Navarro (cristina.duenas@jtsec.es)
Sunwoo Lee and Seunghyun Yoon, Korea Institute of Energy Technology (KENTECH)

References