Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-5598: Bouncy Castle Java library may let attackers execute code
CVE-2026-5598 · published 3 days ago
Summary
The Bouncy Castle Java cryptography library (bcprov-jdk18on and related packages) has a weakness that could allow a malicious user to run unwanted code on your system. Update to the latest patched versions provided by your package manager to protect your applications. Applying the released updates removes this risk.
What to do
- Update bouncycastle org.bouncycastle:bcprov-jdk15to18 to version 1.84.
- Update root io.root.org.bouncycastle:bcprov-jdk18on to version 1.79-root.io.5.
- Update bouncycastle org.bouncycastle:bcprov-jdk18on to version 1.84.
- Update bouncycastle org.bouncycastle:bcprov-jdk14 to version 1.84.
- Update root io.root.org.bouncycastle:bcprov-jdk18on to version 1.83-root.io.1.
- Update root io.root.org.bouncycastle:bcprov-jdk18on to version 1.81-root.io.1.
- Update root io.root.org.bouncycastle:bcprov-jdk18on to version 1.75-root.io.1.
- Update bouncycastle org.bouncycastle:bcprov-jdk18on to version 1.83-aikido.2.
- Update bouncycastle org.bouncycastle:bcprov-jdk14 to version 1.81.1.
- Update bouncycastle org.bouncycastle:bcprov-jdk15to18 to version 1.80.2.
- Update root io.root.org.bouncycastle:bcprov-jdk18on to version 1.75-root.io.2.
- Update root io.root.org.bouncycastle:bcprov-jdk18on to version 1.75-root.io.5.
- Update bouncycastle org.bouncycastle:bcprov-jdk18on to version 1.75-aikido.5.
- Update root io.root.org.bouncycastle:bcprov-jdk18on to version 1.81-root.io.3.
- Update bouncycastle org.bouncycastle:bcprov-jdk18on to version 1.81-aikido.3.
- Update org.bouncycastle:bcprov-jdk18on to version 1.84-aikido.1.
- Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.84-root.io.1.
- Update legion of the bouncy castle inc. bc-java to version 1.80.2 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | bouncycastle | All versions |
| Debian:12 | debian | bouncycastle | All versions |
| Debian:13 | debian | bouncycastle | All versions |
| Debian:14 | debian | bouncycastle | All versions |
| maven | bouncycastle | org.bouncycastle:bcprov-jdk15to18 |
>= 1.71, < 1.84 >= 1.71, < 1.80.2 Fix: upgrade to 1.84
|
| – | legion of the bouncy castle inc. | bc-java | < 1.80.2 |
| Root:Maven | root | io.root.org.bouncycastle:bcprov-jdk18on |
< 1.79-root.io.5 < 1.83-root.io.1 < 1.81-root.io.1 < 1.75-root.io.1 < 1.75-root.io.2 < 1.75-root.io.5 < 1.81-root.io.3 Fix: upgrade to 1.79-root.io.5
|
| maven | bouncycastle | org.bouncycastle:bcprov-jdk18on |
>= 1.71, < 1.84 >= 1.82, < 1.84 Fix: upgrade to 1.84
|
| maven | bouncycastle | org.bouncycastle:bcprov-jdk14 |
>= 1.71, < 1.84 >= 1.81, < 1.81.1 Fix: upgrade to 1.84
|
| Root:Maven | bouncycastle | org.bouncycastle:bcprov-jdk18on |
< 1.83-aikido.2 < 1.75-aikido.5 < 1.81-aikido.3 Fix: upgrade to 1.83-aikido.2
|
| Root:Maven | – | org.bouncycastle:bcprov-jdk18on |
< 1.84-aikido.1 Fix: upgrade to 1.84-aikido.1
|
| Root:Maven | – | io.root.org.bouncycastle:bcprov-jdk18on |
< 1.84-root.io.1 Fix: upgrade to 1.84-root.io.1
|
Original advisory text
CVE-2026-5598 in org.bouncycastle:bcprov-jdk18on - Patched by Root
Root has patched CVE-2026-5598 in the org.bouncycastle:bcprov-jdk18on package for Root:Maven. Multiple fixed versions available.
References
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905998
- https://access.redhat.com/errata/RHSA-2026:18055 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5598.j... Vendor Advisory
- https://github.com/bcgit/bc-java/commit/8692e6b2b191fc4aafa32545c7a78bdb9bf110c5 Patch
- https://github.com/advisories/GHSA-p93r-85wp-75v3
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5598.json URL
- https://access.redhat.com/errata/RHSA-2026:53644 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:18054 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:12267 Vendor Advisory
- https://github.com/bcgit/bc-java/commit/94abbd56413dfdac651fd878bc60253871ef5e87 Patch
- https://access.redhat.com/errata/RHSA-2026:53806 Vendor Advisory
- https://www.bouncycastle.org/download/bouncy-castle-java/ URL
- https://github.com/bcgit/bc-java/wiki/CVE-2026-5598
- https://access.redhat.com/security/cve/CVE-2026-5598 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-5598 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2458635 Third Party Advisory
- https://github.com/bcgit/bc-java Product
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905598 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:12269 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:18059 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:53645 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:53646 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-5598 Vendor Advisory
Severity
9.1
Critical
CVSS 4.0: 10.0 (NVD)
CVSS 3.1: 7.5 (OSV)
Exploitation
EPSS <1%
Type
CWE-385Covert Timing Channel
Timeline
Published24 Sep 2026
Updated27 Sep 2026
First seen16 Apr 2026
Sources
DEBIAN-CVE-2026-5598 · OSV
CVE-2026-5598 · OSV
GHSA-p93r-85wp-75v3 · GHSA
CVE-2026-5598 · NVD
CVE-2026-5598 · MITRE
Track software like this
Free during beta