In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
{
"cwe_ids": [
"CWE-354"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12816.json",
"cna_assigner": "bcorg"
}[
{
"id": "CVE-2026-12816-228f0e71",
"signature_version": "v1",
"target": {
"file": "core/src/test/java/org/bouncycastle/crypto/test/ECIESTest.java"
},
"deprecated": false,
"source": "https://github.com/bcgit/bc-java/commit/6d9e4bbaee9409713ada167e5f901554cbb084ac",
"digest": {
"line_hashes": [
"12286259687050575229296683165244447642",
"333777176401813269484024012765568856142",
"169527211862627727946266417483850304161",
"273074089352199553117741146448631648083",
"301734875555428388806683935126952525546",
"109391545642665904104121926837062339161",
"329942142184009405323326196099659975311",
"82672375765569238414935117013073813271",
"316667336811007258297602574029218181368",
"176536389688541304813118096142318710078"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"source": "https://github.com/bcgit/bc-java/commit/6d9e4bbaee9409713ada167e5f901554cbb084ac",
"target": {
"file": "core/src/main/java/org/bouncycastle/crypto/engines/IESEngine.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"293969212190527329221926637732999916368",
"41499694834007515671395711484743739887",
"64827145259641411542131372628914071863",
"180367721764810433593426828327176598326",
"168436458250902241175230047162984817923",
"132132251421550024796370799550294755915",
"58603157903586708812716014904207906604",
"1513752492766316727298870644893712412",
"261739843364149528787291411753744630007",
"269753771756450133595081107522174968254",
"233653678296904439779522386053376593136",
"244637652468920807298634032480762129996",
"38064928630513668236892097846663250388",
"274091415540700430860534070677973595895",
"175586789904551005474581485595897139352",
"158087558957549840588140505560366903300",
"180367721764810433593426828327176598326",
"168436458250902241175230047162984817923",
"132132251421550024796370799550294755915",
"58603157903586708812716014904207906604",
"1513752492766316727298870644893712412",
"261739843364149528787291411753744630007",
"269753771756450133595081107522174968254",
"233653678296904439779522386053376593136",
"58776290462259345479804900066229945703",
"105988070880264724867591314110613282614",
"48197964834373264991007164130497019958",
"250237296400504758329293754435434615416",
"323887388262990516327055875232228152350"
],
"threshold": 0.9
},
"id": "CVE-2026-12816-4f7e35fb",
"signature_version": "v1",
"signature_type": "Line"
},
{
"source": "https://github.com/bcgit/bc-java/commit/6d9e4bbaee9409713ada167e5f901554cbb084ac",
"target": {
"file": "core/src/main/java/org/bouncycastle/crypto/engines/IESEngine.java",
"function": "encryptBlock"
},
"deprecated": false,
"digest": {
"function_hash": "292371127808127455713179976016968776936",
"length": 2105.0
},
"id": "CVE-2026-12816-51dbd394",
"signature_version": "v1",
"signature_type": "Function"
},
{
"target": {
"file": "core/src/main/java/org/bouncycastle/crypto/engines/IESEngine.java",
"function": "decryptBlock"
},
"deprecated": false,
"digest": {
"function_hash": "320278328325647757176244077734801042929",
"length": 2365.0
},
"signature_version": "v1",
"id": "CVE-2026-12816-932fa2a2",
"source": "https://github.com/bcgit/bc-java/commit/6d9e4bbaee9409713ada167e5f901554cbb084ac",
"signature_type": "Function"
},
{
"digest": {
"function_hash": "113571361939382747423509396468173814464",
"length": 3045.0
},
"signature_version": "v1",
"target": {
"file": "core/src/test/java/org/bouncycastle/crypto/test/ECIESTest.java",
"function": "doStaticTest"
},
"deprecated": false,
"id": "CVE-2026-12816-bbf9b856",
"source": "https://github.com/bcgit/bc-java/commit/6d9e4bbaee9409713ada167e5f901554cbb084ac",
"signature_type": "Function"
},
{
"source": "https://github.com/bcgit/bc-java/commit/6d9e4bbaee9409713ada167e5f901554cbb084ac",
"target": {
"file": "core/src/test/java/org/bouncycastle/crypto/test/ECIESTest.java",
"function": "performTest"
},
"deprecated": false,
"digest": {
"function_hash": "118827998654959518285846714562025903220",
"length": 1030.0
},
"id": "CVE-2026-12816-c760cf82",
"signature_version": "v1",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-12816.json"
"2026-08-12T15:33:29Z"