CVE-2026-12852: MLS wire decoder allocates attacker-declared opaque length before bounds check
Published Aug 3, 2026
·Updated
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
Affected Software
1 affected component
Bouncy Castle Bouncy Castle for Java<1.85
Event History
Aug 3, 2026
CVE Published
via MITRE·02:55 AM
Data Sourced
via MITRE·02:55 AM
DescriptionWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-12852?
The severity of CVE-2026-12852 is high, with a score of 8.7.
2
How do I fix CVE-2026-12852?
To fix CVE-2026-12852, update Bouncy Castle for Java to version 1.85 or later.
3
What type of vulnerability is CVE-2026-12852?
CVE-2026-12852 is a memory allocation vulnerability where attacker-declared lengths are allocated before bounds checks.
4
Which software is affected by CVE-2026-12852?
The affected software is Bouncy Castle for Java, specifically versions prior to 1.85.
5
When was CVE-2026-12852 published?
CVE-2026-12852 was published on August 3, 2026.