Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5598

30
FAUCET Score

OVERVIEW CVE-2026-5598 is a covert timing channel vulnerability discovered in Legion of the Bouncy Castle Inc.'s BC-JAVA cryptographic library, specifically within the FrodoEngine.Java component of the core modules. The vulnerability affects BC-JAVA versions 1.71 through 1.83, impacting all users of these versions. SEVERITY The CVSS score is not yet assigned; however, the FAUCET Risk Score of 52.0/100 indicates moderate severity. As a timing channel vulnerability, this issue could potentially allow attackers to extract sensitive cryptographic information through side-channel analysis by measuring execution time variations. The attack would require access to measure precise timing differences during cryptographic operations, suggesting moderate attack complexity. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is currently available. Community attention remains minimal, as indicated by the inactive status on security tracking lists and an extremely low EPSS score of 0.00018, suggesting this is not a prioritized threat in real-world attack scenarios.

Impacted Technologies

VendorProductVersion(s)CPE
Legion Of The Bouncy Castle Inc.BC-JAVA
>= 1.71, < 1.80.2, >= 1.81, < 1.81.1, >= 1.82, < 1.84CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

8.9HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Red

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.69%
Probability of exploitation in next 30 days
EPSS Percentile
49.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0069 is in the 25th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk15to18Fixed in: 1.80.2
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk14Fixed in: 1.81.1
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk18onFixed in: 1.84

Vendor Advisories (1)

mavenGHSA-p93r-85wp-75v3high

Bouncy Castle Has Covert Timing Channel Vulnerability

Apr 17, 2026

References

access.redhat.com / errata/RHSA-2026:12267
access.redhat.com / errata/RHSA-2026:12269
access.redhat.com / errata/RHSA-2026:18054
access.redhat.com / errata/RHSA-2026:18055
access.redhat.com / errata/RHSA-2026:18059
access.redhat.com / security/cve/CVE-2026-5598
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-5598.json
github.com / bcgit/bc-java/commit/8692e6b2b191fc4aafa32545c7a78bdb9bf110c5
github.com / bcgit/bc-java/commit/94abbd56413dfdac651fd878bc60253871ef5e87
github.com / bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905598