CVE-2026-71883
Last modified
CVE-2026-71883 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM and GCM-SIV released the caller's key, IV and additional authenticated data arrays with JNI's ReleaseByteArrayElements in mode 0, which commits the native copy back into the Java array. Those arrays are read-only to the native code, and on a JVM that returns a copy rather than a pin the copy still holds the input bytes as they were read.
Description
In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM and GCM-SIV released the caller's key, IV and additional authenticated data arrays with JNI's ReleaseByteArrayElements in mode 0, which commits the native copy back into the Java array. Those arrays are read-only to the native code, and on a JVM that returns a copy rather than a pin the copy still holds the input bytes as they were read. The output buffer is taken through a separate critical region and committed first, so where an application passed the same Java array as both an input and the destination - encrypting in place over KeyParameter.getKey(), for example - the later mode-0 release of the key wrote the unchanged key bytes over the ciphertext that had just been produced. The call still returned the correct output length, so an application encrypting in place over its own key array was handed the raw AES key where it expected ciphertext, with nothing in the API to indicate it, and would transmit or store the key in place of the message. The read-only input arrays are now released with JNI_ABORT, freeing the native copy without copying it back, and mode 0 is reserved for arrays the native code wrote. The pure-Java packet ciphers and the streaming native modes are not affected. Bouncy Castle for Java (bcprov) is not affected, as it ships no native implementations.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | >= 2.73.4, < 2.73.13 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-71883?
How severe is CVE-2026-71883?
How do I fix CVE-2026-71883?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-71870pypdf is a free and open-source pure-python PDF library. Pri…4.8
- CVE-2026-71871Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71878Missing authentication in initial setup functionality left e…9.2
- CVE-2026-71879Missing authentication in initial setup functionality left e…9.1
- CVE-2026-7188Improper neutralization of special elements used in an SQL c…9.8
- CVE-2026-71880Interpretation of untrusted input in template engine in GBIF…7.6
- CVE-2026-71885In Bouncy Castle for Java before 1.86, the Messaging Layer S…9.2
- CVE-2026-71886In Bouncy Castle for Java before 1.86, the high-level OpenPG…8.2
- CVE-2026-71887In Bouncy Castle for Java before 1.86, the high-level OpenPG…8.2
- CVE-2026-71888In Bouncy Castle for Java before 1.86, the streaming CMS Aut…8.7
- CVE-2026-71889In Bouncy Castle for Java before 1.86, neither copy of PKIXC…8.7
- CVE-2026-7189Insertion of sensitive information into sent data vulnerabil…7.5
Are you affected by CVE-2026-71883?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
