CVE-2026-5598: Legion Of The Bouncy Castle Inc Bc-Java

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

Affected products

  • Legion Of The Bouncy Castle Inc Bc-Java: from 1.71, before 1.80.2 (fixed in 1.80.2); from 1.81, before 1.81.1 (fixed in 1.81.1); from 1.82, before 1.84 (fixed in 1.84)
  • Red Hat Cryostat 4
  • Red Hat Openshift Developer Tools And Services
  • Red Hat Red Hat Amq Broker 7
  • Red Hat Red Hat Amq Clients
  • Red Hat Red Hat Build Of Apache Camel 4 For Quarkus 3
  • Red Hat Red Hat Build Of Apache Camel For Spring Boot 4
  • Red Hat Red Hat Build Of Apicurio Registry 3
  • Red Hat Red Hat Build Of Debezium 2
  • Red Hat Red Hat Build Of Debezium 3
  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat Build Of Quarkus
  • Red Hat Red Hat Data Grid 8
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Fuse 7
  • Red Hat Red Hat JBoss Enterprise Application Platform 7
  • Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 7: before 0:1.84.0-1.redhat_00001.1.el7eap (fixed in 0:1.84.0-1.redhat_00001.1.el7eap); before 0:2.16.0-22.redhat_00057.1.el7eap (fixed in 0:2.16.0-22.redhat_00057.1.el7eap); before 0:2.3.14-11.SP11_redhat_00001.1.el7eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el7eap); before 0:1.5.26-2.Final_redhat_00001.1.el7eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el7eap); before 0:2.18.8-1.redhat_00003.1.el7eap (fixed in 0:2.18.8-1.redhat_00003.1.el7eap); before 0:5.0.31-3.SP2_redhat_00001.1.el7eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el7eap); …
  • Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 8: before 0:1.84.0-1.redhat_00001.1.el8eap (fixed in 0:1.84.0-1.redhat_00001.1.el8eap); before 0:2.16.0-22.redhat_00057.1.el8eap (fixed in 0:2.16.0-22.redhat_00057.1.el8eap); before 0:2.3.14-11.SP11_redhat_00001.1.el8eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el8eap); before 0:1.5.26-2.Final_redhat_00001.1.el8eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el8eap); before 0:2.18.8-1.redhat_00003.1.el8eap (fixed in 0:2.18.8-1.redhat_00003.1.el8eap); before 0:5.0.31-3.SP2_redhat_00001.1.el8eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el8eap); …
  • Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 9: before 0:1.84.0-1.redhat_00001.1.el9eap (fixed in 0:1.84.0-1.redhat_00001.1.el9eap); before 0:2.16.0-22.redhat_00057.1.el9eap (fixed in 0:2.16.0-22.redhat_00057.1.el9eap); before 0:2.3.14-11.SP11_redhat_00001.1.el9eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el9eap); before 0:1.5.26-2.Final_redhat_00001.1.el9eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el9eap); before 0:2.18.8-1.redhat_00003.1.el9eap (fixed in 0:2.18.8-1.redhat_00003.1.el9eap); before 0:5.0.31-3.SP2_redhat_00001.1.el9eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el9eap); …
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.1.7.ga: before 1.84.0.redhat-00001 (fixed in 1.84.0.redhat-00001)
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 8: before 0:1.84.0-1.redhat_00001.1.el8eap (fixed in 0:1.84.0-1.redhat_00001.1.el8eap)
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 9: before 0:1.84.0-1.redhat_00001.1.el9eap (fixed in 0:1.84.0-1.redhat_00001.1.el9eap)
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
  • and 7 more

Published 2026-04-15. Last modified 2026-09-18.