CVE-2026-5598

ADVISORY - github

Summary

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java.

This issue only affects users of the FrodoKEM algorithm involved in the decryption of encapsulations.

This issue affects BC-JAVA: from 1.71 to 1.80.1, 1.81, 1.82 to 1.83.

Fixed versions: 1.80.2, 1.81.1, 1.84

EPSS Score: 0.00512 (0.396)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Covert Timing Channel

ADVISORY - github

Covert Timing Channel


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in