Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue only affects users of the FrodoKEM algorithm involved in the decryption of encapsulations. This issue affects BC-JAVA: from 1.71 to 1.80.1, 1.81, 1.82 to 1.83. Fixed versions: 1.80.2, 1.81.1, 1.84
Update org.bouncycastle:bcprov-jdk14 to 1.81.1; org.bouncycastle:bcprov-jdk15to18 to 1.80.2; org.bouncycastle:bcprov-jdk18on to 1.84 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanBouncy Castle Has Covert Timing Channel Vulnerability affects org.bouncycastle:bcprov-jdk14 (maven), org.bouncycastle:bcprov-jdk15to18 (maven), org.bouncycastle:bcprov-jdk18on (maven). Severity is high. Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue only affects users of the FrodoKEM algorithm involved in the decryption of encapsulations. This issue affects BC-JAVA: from 1.71 to 1.80.1, 1.81, 1.82 to 1.83. Fixed versions: 1.80.2, 1.81.1, 1.84
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.bouncycastle:bcprov-jdk14maven |
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue only affects users of the FrodoKEM algorithm involved in the decryption of encapsulations. This issue affects BC-JAVA: from 1.71 to 1.80.1, 1.81, 1.82 to 1.83. Fixed versions: 1.80.2, 1.81.1, 1.84
Update org.bouncycastle:bcprov-jdk14 to 1.81.1; org.bouncycastle:bcprov-jdk15to18 to 1.80.2; org.bouncycastle:bcprov-jdk18on to 1.84 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanBouncy Castle Has Covert Timing Channel Vulnerability affects org.bouncycastle:bcprov-jdk14 (maven), org.bouncycastle:bcprov-jdk15to18 (maven), org.bouncycastle:bcprov-jdk18on (maven). Severity is high. Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue only affects users of the FrodoKEM algorithm involved in the decryption of encapsulations. This issue affects BC-JAVA: from 1.71 to 1.80.1, 1.81, 1.82 to 1.83. Fixed versions: 1.80.2, 1.81.1, 1.84
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.bouncycastle:bcprov-jdk14maven |
| >=1.81,<1.81.1 |
| 1.81.1 |
| org.bouncycastle:bcprov-jdk15to18maven | >=1.71,<1.80.2 | 1.80.2 |
|---|
| org.bouncycastle:bcprov-jdk18onmaven | >=1.82,<1.84 | 1.84 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=1.81,<1.81.1 |
| 1.81.1 |
| org.bouncycastle:bcprov-jdk15to18maven | >=1.71,<1.80.2 | 1.80.2 |
|---|
| org.bouncycastle:bcprov-jdk18onmaven | >=1.82,<1.84 | 1.84 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard