OVERVIEW CVE-2026-5598 is a covert timing channel vulnerability discovered in Legion of the Bouncy Castle Inc.'s BC-JAVA cryptographic library, specifically within the FrodoEngine.Java component of the core modules. The vulnerability affects BC-JAVA versions 1.71 through 1.83, impacting all users of these versions. SEVERITY The CVSS score is not yet assigned; however, the FAUCET Risk Score of 52.0/100 indicates moderate severity. As a timing channel vulnerability, this issue could potentially allow attackers to extract sensitive cryptographic information through side-channel analysis by measuring execution time variations. The attack would require access to measure precise timing differences during cryptographic operations, suggesting moderate attack complexity. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is currently available. Community attention remains minimal, as indicated by the inactive status on security tracking lists and an extremely low EPSS score of 0.00018, suggesting this is not a prioritized threat in real-world attack scenarios.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Legion Of The Bouncy Castle Inc. | BC-JAVA | >= 1.71, < 1.80.2, >= 1.81, < 1.81.1, >= 1.82, < 1.84CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.