In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
{
"cwe_ids": [
"CWE-354"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12802.json",
"cna_assigner": "bcorg",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.0.12"
},
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.12"
},
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.12"
}
],
"source": "AFFECTED_FIELD"
}
]
}"2026-08-08T20:32:08Z"
[
{
"id": "CVE-2026-12802-154ae4ce",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 428.0,
"function_hash": "82155891828826495303618444194621781818"
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"function": "extractSecretKey",
"file": "pkix/src/main/java/org/bouncycastle/cms/bc/BcKEKRecipient.java"
}
},
{
"id": "CVE-2026-12802-1fcb7658",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 878.0,
"function_hash": "81324936952148024546993637716925465326"
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"function": "extractSecretKey",
"file": "pkix/src/main/java/org/bouncycastle/cms/jcajce/JceKEMRecipient.java"
}
},
{
"id": "CVE-2026-12802-256d0600",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"147440542542738606739368812488218513723",
"210686587172122766953060831531953413281",
"248652155709433980883254496216268024072",
"43793854403961837730401005111920768583",
"94702306491044067700982159814218537090",
"230691305857519436761474175626174781246",
"239780368233721030989545143187919806884"
]
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"file": "pkix/src/test/java/org/bouncycastle/cms/test/AuthEnvelopedDataTest.java"
}
},
{
"id": "CVE-2026-12802-29336357",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"265130412535566546554108307334083293395",
"117092654511637224432103664710497266873",
"221546379067033197438950231097520947580",
"88849211705335451407314882468973309981",
"87950990634181140917966109985356601448",
"233528789817258455455782773843422345456",
"31677515899552502601523046753537479195",
"307764040591825710363215915313034715105",
"50430014844346840419435337614482407794"
]
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cms/AbstractRecipient.java"
}
},
{
"id": "CVE-2026-12802-4cf629c3",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 2242.0,
"function_hash": "300637178174476399954395256637512395984"
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"function": "extractSecretKey",
"file": "pkix/src/main/java/org/bouncycastle/cms/jcajce/JceKeyAgreeRecipient.java"
}
},
{
"id": "CVE-2026-12802-6eebef37",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"306872504305657341893832973173251540272",
"39711913251296924761709912028046716364",
"55389156090223219405269059955522886658",
"254417332376196878103811302856912097488",
"178075840031038681952622627913307392273",
"190656889889984321609152182097568029070"
]
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cms/jcajce/JceKEMRecipient.java"
}
},
{
"id": "CVE-2026-12802-89850f2c",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"306872504305657341893832973173251540272",
"39711913251296924761709912028046716364",
"55389156090223219405269059955522886658",
"267508588816475284210384486665808423512",
"186900064241281760231234620175162406075",
"168074312008622550252771445604898310320"
]
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cms/jcajce/JceKeyTransRecipient.java"
}
},
{
"id": "CVE-2026-12802-8e7845e1",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 2833.0,
"function_hash": "306748684655945404097631202344594887369"
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"function": "extractSecretKey",
"file": "pkix/src/main/java/org/bouncycastle/cms/jcajce/JceKeyTransRecipient.java"
}
},
{
"id": "CVE-2026-12802-9068f20e",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"285575058979167854510584257309611587188",
"319812125529650428922422833994809109248",
"3437227293895106545876303722835327320"
]
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cms/bc/BcPasswordRecipient.java"
}
},
{
"id": "CVE-2026-12802-90bc314b",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"230065187043983282870671709613359414901",
"240772492148473316291622286137049612900",
"198944537431576507266386517226143135075",
"157528523111634006143597509135626660547",
"250700127535340241830872417857088232491",
"197251306482624915218468068231307945640"
]
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cms/jcajce/JcePasswordRecipient.java"
}
},
{
"id": "CVE-2026-12802-91cc482c",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 566.0,
"function_hash": "17990067262524501988239901427073912480"
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"function": "extractSecretKey",
"file": "pkix/src/main/java/org/bouncycastle/cms/jcajce/JceKEKRecipient.java"
}
},
{
"id": "CVE-2026-12802-93fcaaa0",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"10486459341047951737330784752021055426",
"67568031696806337370804839899652718326",
"1090076694521962852446375423136746064",
"267951700410483991301820912863351684142",
"149552258430099766103052186108160188053",
"332065307124839042452541375729518987350"
]
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cms/jcajce/JceKEKRecipient.java"
}
},
{
"id": "CVE-2026-12802-99be241c",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 649.0,
"function_hash": "56838190043851995156819416998652566652"
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"function": "extractSecretKey",
"file": "pkix/src/main/java/org/bouncycastle/cms/bc/BcPasswordRecipient.java"
}
},
{
"id": "CVE-2026-12802-a9d92fa3",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"316327730877718205807825606165730342152",
"175172795630293635389511642299815721531",
"185430927805382905315051123716423620735",
"46113485582598649581348754758974713757",
"65093240193177361446488249282907368365",
"239260441837464319465054988933150928048"
]
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cms/jcajce/JceKeyAgreeRecipient.java"
}
},
{
"id": "CVE-2026-12802-bdabcd1b",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"337687253958205177368410337714494585169",
"271817227627490363383224754917378673756",
"156035031071659496004178288419132538911"
]
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cms/bc/BcKeyTransRecipient.java"
}
},
{
"id": "CVE-2026-12802-c25bf07b",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 728.0,
"function_hash": "93726280761793529678849502490195857981"
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"function": "extractSecretKey",
"file": "pkix/src/main/java/org/bouncycastle/cms/jcajce/JcePasswordRecipient.java"
}
},
{
"id": "CVE-2026-12802-c915c4dc",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 474.0,
"function_hash": "296373650193779348732705739878373433870"
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"function": "extractSecretKey",
"file": "pkix/src/main/java/org/bouncycastle/cms/bc/BcKeyTransRecipient.java"
}
},
{
"id": "CVE-2026-12802-f306d963",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"46113485582598649581348754758974713757",
"65093240193177361446488249282907368365",
"201919484548997870912461852156483275344"
]
},
"source": "https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cms/bc/BcKEKRecipient.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12802.json"