CVE-2026-12860: RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path
Published Aug 3, 2026
·Updated
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Affected Software
2 affected components
Bouncy Castle Bouncy Castle for Java<1.85
Bouncy Castle for Java LTS<2.73.12
Event History
Aug 3, 2026
CVE Published
via MITRE·02:55 AM
Data Sourced
via MITRE·02:55 AM
DescriptionWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-12860?
CVE-2026-12860 has a severity rating of high, with a CVSS score of 8.7.
2
How do I fix CVE-2026-12860?
To fix CVE-2026-12860, upgrade to Bouncy Castle for Java version 1.85 or Bouncy Castle for Java LTS version 2.73.12 or later.
3
What does CVE-2026-12860 affect?
CVE-2026-12860 affects Bouncy Castle for Java versions prior to 1.85 and Bouncy Castle for Java LTS versions before 2.73.12.
4
What is the exploit path for CVE-2026-12860?
CVE-2026-12860 involves RSA PKCS#1 verification that improperly skips the last two hash bytes in a NULL-omitted path.
5
What is the impact of CVE-2026-12860?
The impact of CVE-2026-12860 can lead to compromised cryptographic verification, potentially allowing unauthorized access.