Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 03 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-java |
|
| Vendors & Products |
Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-java |
Mon, 03 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Mon, 03 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check. | |
| Title | MLS wire decoder allocates attacker-declared opaque length before bounds check | |
| Weaknesses | CWE-789 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: bcorg
Published:
Updated: 2026-08-03T15:11:39.086Z
Reserved: 2026-06-22T03:41:00.916Z
Link: CVE-2026-12852
Updated: 2026-08-03T15:11:33.414Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T10:45:05Z