Threats Tagged 'cve-2026-12803'
View all threats tagged with 'cve-2026-12803'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-12803'
Click on any threat for detailed analysis and mitigation recommendations
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). (CVE-2026-12803)CVE-2026-12803 0 Bouncy Castle for Java versions before 1.85 and LTS versions before 2.73.12 have a vulnerability in the KCCMBlockCipher MAC implementation where the nonce is not bound when Additional Authenticated Data (AAD) is absent. This flaw allows a cross-nonce AEAD forgery attack, undermining the integrity guarantees of the cipher. Join the discussion | GCVE Database | 08/03/2026, 06:31:43 UTC Added: 08/03/2026, 21:22:11 UTC |
CVE-2026-12803: CWE-354 Improper Validation of Integrity Check Value in Legion of the Bouncy Castle Inc. BC-JAVACVE-2026-12803 0 In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12. Join the discussion | CVE Database V5 | 08/03/2026, 02:52:20 UTC Added: 08/03/2026, 04:03:44 UTC |
Showing 1 to 2 of 2 results