CVE-2026-5598

EUVD-2026-22872
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules).
 Non-constant time comparisons risk private key leakage in FrodoKEM.

This issue affects BC-JAVA: from 2.17.3 before 1.84.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---