Bouncy Castle BC-FJA GCM Weakness (gcm128w/gcm512w) 2.1.0-2.1.2
CVE-2026-8149 Published on May 8, 2026

GCM chunking can lead to bad tag exception on decryption
A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w, gcm128w.C, gcm512w.C. This issue affects BC-LTS: from 2.73.0 before 2.73.11; BC-FJA: from 2.1.0 before 2.1.3.

Vendor Advisory NVD

Weakness Type

Inconsistency Between Implementation and Documented Design

The implementation of the product is not consistent with the design as described within the relevant documentation.


Affected Versions

Legion of the Bouncy Castle Inc. BC-LTS: Legion of the Bouncy Castle Inc. BC-FJA:

Exploit Probability

EPSS
0.16%
Percentile
5.28%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.