🔐 CVE Alert

CVE-2026-8149

UNKNOWN 0.0

GCM chunking can lead to bad tag exception on decryption

CVSS Score
0.0
EPSS Score
0.2%
EPSS Percentile
5th

A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w, gcm128w.C, gcm512w.C. This issue affects BC-LTS: from 2.73.0 before 2.73.11; BC-FJA: from 2.1.0 before 2.1.3.

CWE CWE-1068
Vendor legion of the bouncy castle inc.
Product bc-lts
Published May 8, 2026
Last Updated Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for legion of the bouncy castle inc. bc-lts

Be the first to know when new unknown vulnerabilities affecting legion of the bouncy castle inc. bc-lts are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Legion of the Bouncy Castle Inc. / BC-LTS
2.73.0 < 2.73.11
Legion of the Bouncy Castle Inc. / BC-FJA
2.1.0 < 2.1.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908149

Credits

Michael Schäfer, Kiteworks