CVE-2026-12803

Source
https://cve.org/CVERecord?id=CVE-2026-12803
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-12803.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-12803
Downstream
Related
Published
2026-08-03T02:52:20.460Z
Modified
2026-08-14T18:56:22.455702191Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber CVSS Calculator
Summary
KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
Details

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Database specific
{
    "cwe_ids": [
        "CWE-354"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12803.json",
    "cna_assigner": "bcorg"
}
References

Affected packages

Git / github.com/bcgit/bc-java

Affected ranges

Type
GIT
Repo
https://github.com/bcgit/bc-java
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.85"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/bcgit/bc-lts-java
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.73.0"
        },
        {
            "fixed": "2.73.12"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

Other
r1rv73
r1rv74
r1rv75
r1rv76
r1rv77
r1rv78
r1rv80
r1rv81
r1rv82
r1rv83
r1rv84
r2rv73dot0
r2rv73dot1
r2rv73dot10
r2rv73dot11
r2rv73dot3
r2rv73dot4
r2rv73dot6
r2rv73dot8
r2rv73dot9

Database specific

vanir_signatures
[
    {
        "digest": {
            "function_hash": "7859619620194799728679201341619350374",
            "length": 1338.0
        },
        "signature_version": "v1",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/crypto/modes/KCCMBlockCipher.java",
            "function": "processAAD"
        },
        "deprecated": false,
        "id": "CVE-2026-12803-23690617",
        "source": "https://github.com/bcgit/bc-java/commit/697794413ebf7bc5e3fce609a707826ba52981af",
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "core/src/main/java/org/bouncycastle/crypto/modes/KCCMBlockCipher.java",
            "function": "processPacket"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "340073630505974547917171180437211506149",
            "length": 2065.0
        },
        "signature_version": "v1",
        "id": "CVE-2026-12803-2f11a1f4",
        "source": "https://github.com/bcgit/bc-java/commit/697794413ebf7bc5e3fce609a707826ba52981af",
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "core/src/test/java/org/bouncycastle/crypto/test/DSTU7624Test.java"
        },
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "13241190153418575115211978528953783071",
                "68773123159912188478289956958372014665",
                "322200301024387533841575228653024502111",
                "217107377075537363414838838465613957749",
                "185475881173156544269873647740793641214",
                "112282028145144829271635793220694313235",
                "55786641628166949157166300556499813953"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "id": "CVE-2026-12803-30871725",
        "source": "https://github.com/bcgit/bc-java/commit/697794413ebf7bc5e3fce609a707826ba52981af",
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "core/src/main/java/org/bouncycastle/crypto/modes/KCCMBlockCipher.java"
        },
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "42240489653950381934032209227141434017",
                "245170400522677146236471551282861367304",
                "177260572292465906947293309369155931873",
                "185704606458653778969748534924673207144",
                "50928869830128127230614395721960165771",
                "97731694455897932065456692722602612637",
                "108663769404296603634055449591317907553",
                "271635530767887488951777148569267939355",
                "65119549841461085587401391618519727752",
                "330422303916418049487002662006002178847",
                "115362414568935068296400945029314794447",
                "271351299706311998412932683087427870307",
                "132078883961531287791125947789887084777",
                "35375886831783577338721256650660699741",
                "222384511592906643331789783917592823577",
                "273568100553173927308028480153580088270",
                "167171198815327314203091045749921184773",
                "282238348274434270246463019517309926347",
                "21588009919760550339996109834142185385",
                "312652500035829628477688336813764161329",
                "96495454684605035537376219155202953171",
                "258187989350374820795573964039784656828",
                "169989027711387553775515038918047802281",
                "252288185339127650541760491092180695283",
                "314769318678252706128544630536417110584",
                "326049469849102048742983249739736613982",
                "299221706444318657026161744141353190063",
                "314722658510485067924193102512373963258",
                "126533310546340192593651973169586447811"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "id": "CVE-2026-12803-8ad0bf64",
        "source": "https://github.com/bcgit/bc-java/commit/697794413ebf7bc5e3fce609a707826ba52981af",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-12803-9cc10f1e",
        "signature_version": "v1",
        "target": {
            "file": "core/src/test/java/org/bouncycastle/crypto/test/DSTU7624Test.java",
            "function": "CCMModeTests"
        },
        "deprecated": false,
        "source": "https://github.com/bcgit/bc-java/commit/697794413ebf7bc5e3fce609a707826ba52981af",
        "digest": {
            "function_hash": "46708911799259429366893574521313576237",
            "length": 8161.0
        },
        "signature_type": "Function"
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-12803.json"
vanir_signatures_modified
"2026-08-12T15:33:30Z"