The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).
Update org.bouncycastle:bcprov-debug-jdk14 to 1.84; org.bouncycastle:bcprov-debug-jdk15to18 to 1.84; org.bouncycastle:bcprov-debug-jdk18on to 1.84; org.bouncycastle:bcprov-jdk14 to 1.84; org.bouncycastle:bcprov-jdk15to18 to 1.84; org.bouncycastle:bcprov-jdk18on to 1.80.2; org.bouncycastle:bcprov-jdk18on to 1.81.1; org.bouncycastle:bcprov-jdk18on to 1.84 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanBouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks affects org.bouncycastle:bcprov-debug-jdk14 (maven), org.bouncycastle:bcprov-debug-jdk14 (maven), org.bouncycastle:bcprov-debug-jdk14 (maven), org.bouncycastle:bcprov-debug-jdk15to18 (maven), org.bouncycastle:bcprov-debug-jdk15to18 (maven), org.bouncycastle:bcprov-debug-jdk15to18 (maven), org.bouncycastle:bcprov-debug-jdk18on (maven), org.bouncycastle:bcprov-debug-jdk18on (maven), org.bouncycastle:bcprov-debug-jdk18on (maven), org.bouncycastle:bcprov-ext-debug-jdk14 (maven), org.bouncycastle:bcprov-ext-debug-jdk15to18 (maven), org.bouncycastle:bcprov-ext-debug-jdk18on (maven), org.bouncycastle:bcprov-ext-jdk14 (maven), org.bouncycastle:bcprov-ext-jdk15to18 (maven), org.bouncycastle:bcprov-ext-jdk18on (maven), org.bouncycastle:bcprov-jdk14 (maven), org.bouncycastle:bcprov-jdk14 (maven), org.bouncycastle:bcprov-jdk14 (maven), org.bouncycastle:bcprov-jdk15to18 (maven), org.bouncycastle:bcprov-jdk15to18 (maven), org.bouncycastle:bcprov-jdk15to18 (maven), org.bouncycastle:bcprov-jdk18on (maven), org.bouncycastle:bcprov-jdk18on (maven), org.bouncycastle:bcprov-jdk18on (maven). Severity is critical. The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).
The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).
Update org.bouncycastle:bcprov-debug-jdk14 to 1.84; org.bouncycastle:bcprov-debug-jdk15to18 to 1.84; org.bouncycastle:bcprov-debug-jdk18on to 1.84; org.bouncycastle:bcprov-jdk14 to 1.84; org.bouncycastle:bcprov-jdk15to18 to 1.84; org.bouncycastle:bcprov-jdk18on to 1.80.2; org.bouncycastle:bcprov-jdk18on to 1.81.1; org.bouncycastle:bcprov-jdk18on to 1.84 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanBouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks affects org.bouncycastle:bcprov-debug-jdk14 (maven), org.bouncycastle:bcprov-debug-jdk14 (maven), org.bouncycastle:bcprov-debug-jdk14 (maven), org.bouncycastle:bcprov-debug-jdk15to18 (maven), org.bouncycastle:bcprov-debug-jdk15to18 (maven), org.bouncycastle:bcprov-debug-jdk15to18 (maven), org.bouncycastle:bcprov-debug-jdk18on (maven), org.bouncycastle:bcprov-debug-jdk18on (maven), org.bouncycastle:bcprov-debug-jdk18on (maven), org.bouncycastle:bcprov-ext-debug-jdk14 (maven), org.bouncycastle:bcprov-ext-debug-jdk15to18 (maven), org.bouncycastle:bcprov-ext-debug-jdk18on (maven), org.bouncycastle:bcprov-ext-jdk14 (maven), org.bouncycastle:bcprov-ext-jdk15to18 (maven), org.bouncycastle:bcprov-ext-jdk18on (maven), org.bouncycastle:bcprov-jdk14 (maven), org.bouncycastle:bcprov-jdk14 (maven), org.bouncycastle:bcprov-jdk14 (maven), org.bouncycastle:bcprov-jdk15to18 (maven), org.bouncycastle:bcprov-jdk15to18 (maven), org.bouncycastle:bcprov-jdk15to18 (maven), org.bouncycastle:bcprov-jdk18on (maven), org.bouncycastle:bcprov-jdk18on (maven), org.bouncycastle:bcprov-jdk18on (maven). Severity is critical. The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).
AI coding agents often install or upgrade packages automatically in maven. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.bouncycastle:bcprov-debug-jdk14maven | >=1.59,<=1.80.1 | Not reported |
| org.bouncycastle:bcprov-debug-jdk14maven | =1.81.0 | Not reported |
| org.bouncycastle:bcprov-debug-jdk14maven | >=1.82,<=1.83 | 1.84 |
| org.bouncycastle:bcprov-debug-jdk15to18maven | >=1.59,<=1.80.1 | Not reported |
| org.bouncycastle:bcprov-debug-jdk15to18maven | =1.81.0 | Not reported |
| org.bouncycastle:bcprov-debug-jdk15to18maven | >=1.82,<=1.83 | 1.84 |
| org.bouncycastle:bcprov-debug-jdk18onmaven | >=1.59,<=1.80.1 | Not reported |
| org.bouncycastle:bcprov-debug-jdk18onmaven | =1.81.0 | Not reported |
| org.bouncycastle:bcprov-debug-jdk18onmaven | >=1.82,<=1.83 | 1.84 |
| org.bouncycastle:bcprov-ext-debug-jdk14maven | >=1.59,<=1.74 | Not reported |
| org.bouncycastle:bcprov-ext-debug-jdk15to18maven | >=1.59,<=1.77 | Not reported |
| org.bouncycastle:bcprov-ext-debug-jdk18onmaven | >=1.59,<=1.77 | Not reported |
| org.bouncycastle:bcprov-ext-jdk14maven | >=1.59,<=1.78.1 | Not reported |
| org.bouncycastle:bcprov-ext-jdk15to18maven | >=1.59,<=1.78.1 | Not reported |
| org.bouncycastle:bcprov-ext-jdk18onmaven | >=1.59,<=1.78.1 | Not reported |
| org.bouncycastle:bcprov-jdk14maven | >=1.59,<=1.80.1 | Not reported |
| org.bouncycastle:bcprov-jdk14maven | =1.81.0 | Not reported |
| org.bouncycastle:bcprov-jdk14maven | >=1.82,<=1.83 | 1.84 |
| org.bouncycastle:bcprov-jdk15to18maven | >=1.59,<=1.80.1 | Not reported |
| org.bouncycastle:bcprov-jdk15to18maven | =1.81.0 | Not reported |
| org.bouncycastle:bcprov-jdk15to18maven | >=1.82,<=1.83 | 1.84 |
| org.bouncycastle:bcprov-jdk18onmaven | >=1.59,<=1.80.1 | 1.80.2 |
| org.bouncycastle:bcprov-jdk18onmaven | =1.81.0 | 1.81.1 |
| org.bouncycastle:bcprov-jdk18onmaven | >=1.82,<=1.83 | 1.84 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardAI coding agents often install or upgrade packages automatically in maven. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.bouncycastle:bcprov-debug-jdk14maven | >=1.59,<=1.80.1 | Not reported |
| org.bouncycastle:bcprov-debug-jdk14maven | =1.81.0 | Not reported |
| org.bouncycastle:bcprov-debug-jdk14maven | >=1.82,<=1.83 | 1.84 |
| org.bouncycastle:bcprov-debug-jdk15to18maven | >=1.59,<=1.80.1 | Not reported |
| org.bouncycastle:bcprov-debug-jdk15to18maven | =1.81.0 | Not reported |
| org.bouncycastle:bcprov-debug-jdk15to18maven | >=1.82,<=1.83 | 1.84 |
| org.bouncycastle:bcprov-debug-jdk18onmaven | >=1.59,<=1.80.1 | Not reported |
| org.bouncycastle:bcprov-debug-jdk18onmaven | =1.81.0 | Not reported |
| org.bouncycastle:bcprov-debug-jdk18onmaven | >=1.82,<=1.83 | 1.84 |
| org.bouncycastle:bcprov-ext-debug-jdk14maven | >=1.59,<=1.74 | Not reported |
| org.bouncycastle:bcprov-ext-debug-jdk15to18maven | >=1.59,<=1.77 | Not reported |
| org.bouncycastle:bcprov-ext-debug-jdk18onmaven | >=1.59,<=1.77 | Not reported |
| org.bouncycastle:bcprov-ext-jdk14maven | >=1.59,<=1.78.1 | Not reported |
| org.bouncycastle:bcprov-ext-jdk15to18maven | >=1.59,<=1.78.1 | Not reported |
| org.bouncycastle:bcprov-ext-jdk18onmaven | >=1.59,<=1.78.1 | Not reported |
| org.bouncycastle:bcprov-jdk14maven | >=1.59,<=1.80.1 | Not reported |
| org.bouncycastle:bcprov-jdk14maven | =1.81.0 | Not reported |
| org.bouncycastle:bcprov-jdk14maven | >=1.82,<=1.83 | 1.84 |
| org.bouncycastle:bcprov-jdk15to18maven | >=1.59,<=1.80.1 | Not reported |
| org.bouncycastle:bcprov-jdk15to18maven | =1.81.0 | Not reported |
| org.bouncycastle:bcprov-jdk15to18maven | >=1.82,<=1.83 | 1.84 |
| org.bouncycastle:bcprov-jdk18onmaven | >=1.59,<=1.80.1 | 1.80.2 |
| org.bouncycastle:bcprov-jdk18onmaven | =1.81.0 | 1.81.1 |
| org.bouncycastle:bcprov-jdk18onmaven | >=1.82,<=1.83 | 1.84 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard