PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18040 Legion of the Bouncy Castle Inc. CVE debrief

This PatchSiren debrief is based on the supplied CVE record and source item. The CVE record was published on 2026-10-03T09:17:04.360Z and has not been modified since then. The vulnerability in Bouncy Castle for Java before 1.86 allows an attacker to recover information about the HQC private key through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, and its fixed-weight support sampler. The changes made to fix the issue include making the field arithmetic table-free and the sampler branch-free within a batch of candidates. Defenders should assess exposure and prioritize remediation for Java deployments using Bouncy Castle, particularly those

Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for Java deployments using Bouncy Castle, particularly those using versions before 1.86, should assess exposure and prioritize remediation. This includes reviewing and updating inventory to ensure affected versions are identified and remediated, and monitoring for potential side-channel attacks. Additionally, defenders should verify and apply the patch for Bouncy Castle for Java versions before 1.86, and plan vendor-supported updates

Why it matters

The vulnerability in Bouncy Castle for Java before 1.86 allows an attacker to recover information about the HQC private key through side channels, requiring defenders to verify and apply the patch.

  • An attacker may be able to recover information about the HQC private key through side-channel attacks
  • Defenders need to verify and apply the patch to prevent potential attacks
  • Remediation requires updating Bouncy Castle for Java to version 1.86 or later

Technical summary

The vulnerability in Bouncy Castle for Java before 1.86 allows an attacker to recover information about the HQC private key through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, and its fixed-weight support sampler. The changes made to fix the issue include making the field arithmetic table-free and the sampler branch-free within a batch of candidates. The vulnerability can be mitigated by updating Bouncy Castle for Java to version 1.86 or later. The attack requires the ability to observe cache behavior or decapsulation timing, and the sampler re-expands the secret key from its seed on every decapsulation.

Defensive priority

Defenders should prioritize verifying and applying the patch for Bouncy Castle for Java versions before 1.86, as the vulnerability allows an attacker to recover information about the HQC private key through side channels.

Recommended defensive actions

  • Verify and apply the patch for Bouncy Castle for Java versions before 1.86
  • Review and update inventory to ensure affected versions are identified and remediated
  • Monitor for potential side-channel attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details about the vulnerability in Bouncy Castle for Java, including the affected versions and the changes made to fix the issue. However, the corpus does not establish versions, exploitation, impact, or remediation beyond the provided information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18040 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18040

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18040 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18040

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/commit/283acd81048ec9e951032525279d3b58aaf0bb03

    91579145-5d7b-4cc5-b925-a0262ff19630

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9018040

    91579145-5d7b-4cc5-b925-a0262ff19630

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.