CVE-2026-12852
EUVD-2026-5213703.08.2026, 04:16
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bouncycastle | bc-java | 𝑥 < 1.85 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration