🔐 CVE Alert

CVE-2026-8149

UNKNOWN 0.0

GCM chunking can lead to bad tag exception on decryption

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in Legion of the Bouncy Castle Inc. BC-FJA BC-FIPS on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w. This issue affects BC-FJA: from 2.1.0 through 2.1.2.

CWE CWE-1068
Vendor legion of the bouncy castle inc.
Product bc-fja
Published May 8, 2026
Last Updated May 8, 2026
Stay Ahead of the Next One

Get instant alerts for legion of the bouncy castle inc. bc-fja

Be the first to know when new unknown vulnerabilities affecting legion of the bouncy castle inc. bc-fja are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Legion of the Bouncy Castle Inc. / BC-FJA
2.1.0 ≤ 2.1.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
do-not-publish.bouncycastle.org: https://do-not-publish.bouncycastle.org/do_not_publish

Credits

Michael Schäfer, Kiteworks