What is CVE-2026-13505?
This vulnerability in Bouncy Castle for Java FIPS (BC-FJA) involves sensitive key material being zeroized upon garbage collection in AES/DESede engines and DRBGs. It poses a risk of key leakage in affected versions. Organizations should update to bc-fips 1.0.2.7, 2.0.2, or 2.1.3 accordingly.
Azərbaycanca: Bu boşluq Bouncy Castle for Java FIPS (BC-FJA) kitabxanasında həssas açar materialının garbage collection zamanı sıfırlanması ilə bağlıdır. AES, DESede mühərrikləri və DRBG kimi komponentlərdə açar sızması riski yaradır. Təsirlənmiş versiyalar yenilənməli, müvafiq bc-fips 1.0.2.7, 2.0.2 və ya 2.1.3 versiyalarına keçid edilməlidir.
Related CVEs
link basis: shared vendor: Bouncy Castle
FAQ2
In which library was CVE-2026-13505 discovered and what risk does it pose?
The vulnerability is in the Bouncy Castle for Java FIPS (BC-FJA) library. It poses a risk of key leakage due to sensitive key material being zeroized upon garbage collection in AES, DESede engines, and DRBGs.
What versions are recommended to upgrade to in order to mitigate CVE-2026-13505?
Organizations should update to bc-fips versions 1.0.2.7, 2.0.2, or 2.1.3 accordingly.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.