bcprov-jdk15to18 is vulnerable to Timing Attacks
82
High Risk
Poly.toMsg, Poly.compressPoly, and PolyVec.compressPolyVec in the ML-KEM (CRYSTALS-Kyber) implementation divide secret-derived polynomial coefficients by the modulus q in non-constant time. An attacker who can measure the timing of many decapsulations that reuse the same long-term private key can recover that key (KyberSlash1 and KyberSlash2). Encapsulation compression that only touches public ciphertext values is not affected. The fix replaces those divisions with constant-time equivalents.
You are affected if you are using a version that falls within the vulnerable range and your application performs ML-KEM/Kyber decapsulation with a long-lived private key where an attacker can observe timing.
bcprov-jdk15to18 is vulnerable to Timing Attacks in versions 1.73 - 1.77.
Upgrade the org.bouncycastle:bcprov-jdk15to18 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant