CVE-2026-8149 Details
Description
A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w, gcm128w.C, gcm512w.C. This issue affects BC-LTS: from 2.73.0 before 2.73.11; BC-FJA: from 2.1.0 before 2.1.3.
A vulnerability exists in the Legion of the Bouncy Castle BC-FJA BC-FIPS library on Linux systems running x86_64 with AVX and AVX-512f. The issue is related to the GCM (Galois/Counter Mode) implementations in the program files gcm128w and gcm512w. This vulnerability affects BC-FJA versions 2.1.0 through 2.1.2.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908149 | bcorg |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1068 | Inconsistency Between Implementation and Documented Design | bcorg |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | bcorg |
| Jun 17, 2026 | CVE Modified | bcorg |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | CVE Modified | bcorg |
| May 8, 2026 | New CVE Received | bcorg |