In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
{
"cwe_ids": [
"CWE-789"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12185.json",
"cna_assigner": "bcorg"
}[
{
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java",
"function": "engineLoad"
},
"deprecated": false,
"digest": {
"function_hash": "20545814296930775862753775159030708817",
"length": 1355.0
},
"signature_version": "v1",
"id": "CVE-2026-12185-2d277a52",
"source": "https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d",
"signature_type": "Function"
},
{
"source": "https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"126625470973912367559141889636542527441",
"275620721376371710742159725222030818298",
"335242016498211014981637766804596097559",
"321351824931817266576318691490999231091",
"299486651323121999443719075295827198908",
"261235037073052853217655747227500742690",
"208471883241007413473172560891473333419",
"185495402325392415932264034503513802717",
"134520162113536476526522155963741082225",
"161077210254219161107986568255048772915",
"213011583494088306933618817546227365452",
"66411702105623055558407442178581925250",
"296572692676806696265452323326796249599",
"97830118105618779740485470697617290673",
"95441837761028890750461496325328741173",
"75523421855169195773238063479259232675",
"288791983175037994283978786872584510447",
"220643358607853444337495876873457403206",
"61352023725410672525005765199851791911",
"183762398723405440912682393203284276178",
"75523421855169195773238063479259232675",
"288791983175037994283978786872584510447",
"220643358607853444337495876873457403206",
"115258880993266590609643949883776950136",
"233627716672669688559670568734081971432",
"243545147190208054232718200797065608358",
"256611064081867464632497386793914349017",
"196209449970960797796220894978468985607",
"139589678208284178712707229283502017602",
"75474354201899210559220922543691848391",
"251585341678691122346194830799287658970",
"201126594567674772704813505495154454941",
"331615822010715899394602592257665789011",
"100346643228567463340340898921821843914",
"236384179197020838657079760598215301671",
"39794677271442683324684517694973341795",
"327312541752857978314861673731860278775",
"285040118843961941231640330054411336023",
"81467387843572206062320395096514942657",
"105489650659542303204420284291480892411",
"3446961301124516536414517624476845891",
"83815411365380239799564098470749565228",
"248638511297517076754993457007710878503",
"157035496519292754617397200232473558379",
"27425517993934035441761888103014628958",
"232709750944205956897203029143271661411",
"147394977281828138807509398709256353973",
"206326346578925864669278834448808657007",
"266087309997254244671263671282077952659",
"194012424813186087128450110487182615052",
"207620637920550068803522328143223142518",
"220015293549839906171571558862085584183",
"69982411225867825453945739993328667991",
"43830109880371544238984752102479370894",
"206001625593611975921648918930303669742",
"145850916410669285703562723716069114058",
"50603939883895231835068387831360670265",
"214727858775192703697489281110173632458",
"38986076645361470969919693312214851543",
"238541766233414105693743360662819816418",
"126990882814717657730516412606977012669",
"318444921691416156367246125284994064530",
"24398493182312861157053486170346419902",
"157353620633148262010005651451425037774",
"259112975755528912916766816067545110965",
"324459218169897020970321051525669162542"
],
"threshold": 0.9
},
"id": "CVE-2026-12185-34b19082",
"signature_version": "v1",
"signature_type": "Line"
},
{
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java",
"function": "decodeCertificate"
},
"deprecated": false,
"digest": {
"function_hash": "288054803277113755444666547869048928941",
"length": 472.0
},
"signature_version": "v1",
"id": "CVE-2026-12185-35f827ef",
"source": "https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d",
"signature_type": "Function"
},
{
"id": "CVE-2026-12185-476e03b1",
"signature_version": "v1",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java",
"function": "getObject"
},
"deprecated": false,
"source": "https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d",
"digest": {
"function_hash": "178481082840581420363490896444777263761",
"length": 1845.0
},
"signature_type": "Function"
},
{
"id": "CVE-2026-12185-56bfbda5",
"signature_version": "v1",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java",
"function": "decodeKey"
},
"deprecated": false,
"source": "https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d",
"digest": {
"function_hash": "325918687402241025935941627147437471908",
"length": 1081.0
},
"signature_type": "Function"
},
{
"digest": {
"function_hash": "29130605252179874172200646964167497707",
"length": 957.0
},
"signature_version": "v1",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java",
"function": "loadStore"
},
"deprecated": false,
"id": "CVE-2026-12185-70db9d88",
"source": "https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d",
"signature_type": "Function"
},
{
"signature_version": "v1",
"target": {
"file": "prov/src/test/java/org/bouncycastle/jce/provider/test/KeyStoreTest.java",
"function": "performTest"
},
"deprecated": false,
"digest": {
"function_hash": "158242375678900513393310030637263696831",
"length": 157.0
},
"source": "https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d",
"id": "CVE-2026-12185-7bb82e81",
"signature_type": "Function"
},
{
"target": {
"file": "prov/src/test/java/org/bouncycastle/jce/provider/test/KeyStoreTest.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"84790311362871545751676743701834679534",
"170509305370039780630652044377074826619",
"21851042340318058375125050851466058155",
"75766635981602846335404847046623381326",
"198973130602544048547144610590315238724",
"23604481230147967014338401193362755677",
"211200897897925536299229468707483164068"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2026-12185-841418f5",
"source": "https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d",
"signature_type": "Line"
},
{
"id": "CVE-2026-12185-d49db09c",
"signature_version": "v1",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java",
"function": "engineLoad"
},
"deprecated": false,
"source": "https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d",
"digest": {
"function_hash": "204655545377153142160076523593676393542",
"length": 1212.0
},
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-12185.json"
"2026-08-12T15:33:28Z"