What is CVE-2026-12185?
CVE-2026-12185 is a vulnerability in Bouncy Castle for Java versions prior to 1.85 (also affecting LTS before 2.73.12), where BKS/UBER keystore implementations allocate memory from untrusted lengths before performing integrity checks. It is recommended to update the library to a patched version to mitigate the risk.
Azərbaycanca: CVE-2026-12185 Bouncy Castle for Java kitabxanasının 1.85-dən əvvəlki versiyalarında BKS/UBER keystore fayllarında bütövlük yoxlanışından əvvəl etibarsız uzunluq məlumatlarına əsaslanaraq yaddaş ayrılması zəifliyidir; bu, həmçinin 2.73.12-dən əvvəlki LTS versiyalarına da təsir edir. Müdafiə üçün kitabxananı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Bouncy Castle
FAQ2
Which Bouncy Castle for Java versions are affected by CVE-2026-12185?
CVE-2026-12185 affects Bouncy Castle for Java versions prior to 1.85, as well as LTS versions prior to 2.73.12.
How does CVE-2026-12185 bypass security mechanisms?
The vulnerability occurs because BKS/UBER keystore implementations allocate memory from untrusted lengths before performing integrity checks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.