Bouncy Castle BC-FJA GCM Weakness (gcm128w/gcm512w) 2.1.0-2.1.2
CVE-2026-8149 Published on May 8, 2026
GCM chunking can lead to bad tag exception on decryption
A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f.
This vulnerability is associated with program files gcm128w, gcm512w, gcm128w.C, gcm512w.C.
This issue affects BC-LTS: from 2.73.0 before 2.73.11; BC-FJA: from 2.1.0 before 2.1.3.
Weakness Type
Inconsistency Between Implementation and Documented Design
The implementation of the product is not consistent with the design as described within the relevant documentation.
Affected Versions
Legion of the Bouncy Castle Inc. BC-LTS:- Version 2.73.0 and below 2.73.11 is affected.
- Version 2.1.0 and below 2.1.3 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.