CVE-2026-18040: HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-dependent fixed-weight sampler
In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a function of the operand, and its fixed-weight support sampler left its duplicate scan as soon as a collision was found and stored accepted positions at a secret index. Both run on secret inputs during encapsulation and decapsulation, and the sampler re-expands the secret key from its seed on every decapsulation, so an attacker able to observe cache behaviour or decapsulation timing can recover information about the HQC private key. The field arithmetic is now table-free and the sampler branch-free within a batch of candidates, with output and randomness consumption unchanged.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bouncy Castle for Javato a version that resolves this vulnerability.Fixed in 1.86
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using HQC in Bouncy Castle for Java versions before 1.86 are affected when they perform HQC encapsulation or decapsulation on secret inputs. Decapsulation is particularly relevant because the sampler re-expands the secret key from its seed on every decapsulation.
What does an attacker need to exploit the leakage?
An attacker needs the ability to observe cache behaviour or decapsulation timing. The observed behaviour can reveal information derived from the HQC private key.
How can I determine whether my environment is affected?
Check whether the application uses HQC through Bouncy Castle for Java and whether the deployed library version is earlier than 1.86. Systems that do not perform HQC encapsulation or decapsulation are not described as exercising the affected code paths.
What changes in the fixed version?
The GF(2^8) arithmetic is table-free, and the fixed-weight sampler is branch-free within a batch of candidates. The output and randomness consumption are unchanged.