CVE-2026-15997
Last modified
CVE-2026-15997 is a low-severity vulnerability rated 1.7/10 on the CVSS scale. Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/sha3.C. This issue affects BC-LTS: from 2.73.0 before 2.73.12.1. Issue is only applicable if application involved is accepting memoable SHA3 / SHAKE states from potentially untrusted sources.. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/sha3.C. This issue affects BC-LTS: from 2.73.0 before 2.73.12.1. Issue is only applicable if application involved is accepting memoable SHA3 / SHAKE states from potentially untrusted sources.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-LTS | >= 2.73.0, < 2.73.12.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-15997?
How severe is CVE-2026-15997?
How do I fix CVE-2026-15997?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15991The File Manager plugin for WordPress is vulnerable to arbit…8.8
- CVE-2026-15992The WP Password Policy plugin for WordPress is vulnerable to…8.8
- CVE-2026-15993The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contac…5.3
- CVE-2026-15994During an internal security assessment, an improper link fol…7
- CVE-2026-15995IBM Cognos Analytics 12.1.3 GA Version with build number thr…4.2
- CVE-2026-15996A denial of service vulnerability was identified in GitHub E…7.5
- CVE-2026-1600A vulnerability was identified in Bdtask Bhojon All-In-One R…4.3
- CVE-2026-16002The affected product is vulnerable to an Out-of-bounds read,…8.8
- CVE-2026-16003Exposed IOCTL with Insufficient Access Control in Armoury Cr…2
- CVE-2026-16004Exposed IOCTL with Insufficient Access Control in Armoury Cr…5.9
- CVE-2026-16005Release of Invalid Pointer or Reference in Armoury Crate dri…5.8
- CVE-2026-16006Exposure of Sensitive System Information to an Unauthorized …5.7
Are you affected by CVE-2026-15997?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
