CVE-2026-18040: HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-dependent fixed-weight sampler

Published Oct 3, 2026
·
Updated

In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a function of the operand, and its fixed-weight support sampler left its duplicate scan as soon as a collision was found and stored accepted positions at a secret index. Both run on secret inputs during encapsulation and decapsulation, and the sampler re-expands the secret key from its seed on every decapsulation, so an attacker able to observe cache behaviour or decapsulation timing can recover information about the HQC private key. The field arithmetic is now table-free and the sampler branch-free within a batch of candidates, with output and randomness consumption unchanged.

Affected Software

1 affected component
Bouncy Castle Bouncy Castle for Java<1.86

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Bouncy Castle for Java to a version that resolves this vulnerability.

    Fixed in 1.86

Event History

Oct 3, 2026
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using HQC in Bouncy Castle for Java versions before 1.86 are affected when they perform HQC encapsulation or decapsulation on secret inputs. Decapsulation is particularly relevant because the sampler re-expands the secret key from its seed on every decapsulation.

2

What does an attacker need to exploit the leakage?

An attacker needs the ability to observe cache behaviour or decapsulation timing. The observed behaviour can reveal information derived from the HQC private key.

3

How can I determine whether my environment is affected?

Check whether the application uses HQC through Bouncy Castle for Java and whether the deployed library version is earlier than 1.86. Systems that do not perform HQC encapsulation or decapsulation are not described as exercising the affected code paths.

4

What changes in the fixed version?

The GF(2^8) arithmetic is table-free, and the fixed-weight sampler is branch-free within a batch of candidates. The output and randomness consumption are unchanged.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203