CVE-2026-12852: In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-12852
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-128520.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-12852 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Bouncy Castle: Mehrere Schwachstellencert-bund
Recent advisories for In Bouncy Castle
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEU] [hoch] Bouncy Castle: Mehrere Schwachstellencert-bund · 2026-08-03
- unknownCVE-2026-14682: In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a de…nvd · 2026-08-03
- unknownCVE-2026-13586: In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count boun…nvd · 2026-08-03
- unknownCVE-2026-13506: In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard.…nvd · 2026-08-03
- unknownCVE-2026-12860: In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NU…nvd · 2026-08-03
- unknownCVE-2026-12817: In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligne…nvd · 2026-08-03
More from NVD Recent CVEs
- highCVE-2026-59913: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missin…2026-08-03
- highCVE-2026-59912: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Impro…2026-08-03
- unknownCVE-2026-38447: osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The …2026-08-03
- unknownCVE-2026-38446: A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sa…2026-08-03
- unknownCVE-2026-38444: osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header …2026-08-03