CVE-2026-12185: BKS/UBER keystore allocates from untrusted lengths before integrity check
Published Aug 3, 2026
·Updated
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Affected Software
2 affected components
Bouncy Castle Bouncy Castle for Java<1.85
Bouncy Castle for Java LTS<2.73.12
Event History
Aug 3, 2026
CVE Published
via MITRE·12:38 AM
Data Sourced
via MITRE·12:38 AM
DescriptionWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-12185?
CVE-2026-12185 has a risk rating of 37, indicating a significant vulnerability that requires attention.
2
How do I fix CVE-2026-12185?
To remediate CVE-2026-12185, you should upgrade to Bouncy Castle for Java version 1.85 or later, or Bouncy Castle for Java LTS version 2.73.12 or later.
3
What software is affected by CVE-2026-12185?
CVE-2026-12185 affects Bouncy Castle for Java versions prior to 1.85 and Bouncy Castle for Java LTS versions prior to 2.73.12.
4
What type of vulnerability is described by CVE-2026-12185?
CVE-2026-12185 is a vulnerability where the BKS/UBER keystore allocates memory from untrusted lengths before validating its integrity.
5
When was CVE-2026-12185 published?
CVE-2026-12185 was published on August 3, 2026.