In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Mon, 03 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12. | |
| Title | RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: bcorg
Published:
Updated: 2026-08-03T05:56:08.202Z
Reserved: 2026-06-22T07:51:11.945Z
Link: CVE-2026-12860
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T09:00:15Z