Intel

AIKIDO-2026-10630

bcprov-jdk18on is vulnerable to Observable Timing Discrepancy

Observable Timing DiscrepancyCVE-2026-5598 Published Apr 28, 2026

89

High Risk

This Affects:

JAVAbcprov-jdk18on
1.71 - 1.83
Fixed in 1.84
Are you affected? Scan for Free

TL;DR

A covert timing channel vulnerability exists in Legion of the Bouncy Castle Inc. BC-JAVA core across all core modules. The issue is associated with the FrodoEngine.java component and affects BC-JAVA versions 1.71 through 1.83, fixed in 1.84.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

bcprov-jdk18on is vulnerable to Observable Timing Discrepancy in versions 1.71 - 1.83.

How to fix this

Upgrade the org.bouncycastle:bcprov-jdk18on library to the patch version.