Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 03 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-fja Legion Of The Bouncy Castle Inc. bc-java Legion Of The Bouncy Castle Inc. bc-lts-java |
|
| Vendors & Products |
Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-fja Legion Of The Bouncy Castle Inc. bc-java Legion Of The Bouncy Castle Inc. bc-lts-java |
Mon, 03 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Mon, 03 Aug 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series). | |
| Title | CCM-family modes write plaintext to caller buffer before tag check | |
| Weaknesses | CWE-354 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: bcorg
Published:
Updated: 2026-08-03T15:35:41.256Z
Reserved: 2026-06-28T01:21:46.334Z
Link: CVE-2026-58061
Updated: 2026-08-03T15:35:36.453Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T15:52:16Z