Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-12860

Опубликовано: 03 авг. 2026
Источник: debian

Описание

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
bouncycastleunfixedpackage

Примечания

  • https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012860

  • Fixed by: https://github.com/bcgit/bc-java/commit/ea5970ea9b2fb91d763b904692fd21089ca3e396 (r1rv85)

Связанные уязвимости

ubuntu
24 дня назад

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

nvd
24 дня назад

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

github
24 дня назад

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

suse-cvrf
21 день назад

Security update for bouncycastle

suse-cvrf
16 дней назад

Security update for bouncycastle