{"id":"CVE-2026-12185","summary":"BKS/UBER keystore allocates from untrusted lengths before integrity check","details":"In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.","modified":"2026-08-14T18:56:38.136855982Z","published":"2026-08-03T00:38:01.609Z","related":["SUSE-SU-2026:23127-1","SUSE-SU-2026:23150-1","SUSE-SU-2026:3559-1","openSUSE-SU-2026:11445-1","openSUSE-SU-2026:21538-1"],"database_specific":{"cna_assigner":"bcorg","cwe_ids":["CWE-789"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12185.json"},"references":[{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-lts/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12185.json"},{"type":"ADVISORY","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012185"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12185"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-lts-java"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bcgit/bc-java","events":[{"introduced":"0"},{"fixed":"57fbd3c501f7a369f64eda311d6a709fc0bcae84"},{"fixed":"7bbd7fe5f44132e5b6140a2914435c12430eeb3d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.85"}],"source":["DESCRIPTION","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/bcgit/bc-lts-java","events":[{"introduced":"468b5082f3f0971e80bf9edb7029c17b39b9ba0c"},{"fixed":"f101b232c5d3e07ecdd504210a57e43831d6cd65"}],"database_specific":{"extracted_events":[{"introduced":"2.73.0"},{"fixed":"2.73.12"}],"source":"AFFECTED_FIELD"}}],"versions":["r1rv84","r1rv81","r1rv83","r1rv82","r1rv80","r1rv78","r1rv77","r1rv76","r1rv75","r1rv74","r1rv73","r2rv73dot11","r2rv73dot10","r2rv73dot9","r2rv73dot8","r2rv73dot6","r2rv73dot4","r2rv73dot3","r2rv73dot1","r2rv73dot0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-12185.json","vanir_signatures_modified":"2026-08-12T15:33:28Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d","target":{"file":"prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java","function":"engineLoad"},"deprecated":false,"digest":{"function_hash":"20545814296930775862753775159030708817","length":1355},"id":"CVE-2026-12185-2d277a52"},{"target":{"file":"prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java"},"deprecated":false,"digest":{"line_hashes":["126625470973912367559141889636542527441","275620721376371710742159725222030818298","335242016498211014981637766804596097559","321351824931817266576318691490999231091","299486651323121999443719075295827198908","261235037073052853217655747227500742690","208471883241007413473172560891473333419","185495402325392415932264034503513802717","134520162113536476526522155963741082225","161077210254219161107986568255048772915","213011583494088306933618817546227365452","66411702105623055558407442178581925250","296572692676806696265452323326796249599","97830118105618779740485470697617290673","95441837761028890750461496325328741173","75523421855169195773238063479259232675","288791983175037994283978786872584510447","220643358607853444337495876873457403206","61352023725410672525005765199851791911","183762398723405440912682393203284276178","75523421855169195773238063479259232675","288791983175037994283978786872584510447","220643358607853444337495876873457403206","115258880993266590609643949883776950136","233627716672669688559670568734081971432","243545147190208054232718200797065608358","256611064081867464632497386793914349017","196209449970960797796220894978468985607","139589678208284178712707229283502017602","75474354201899210559220922543691848391","251585341678691122346194830799287658970","201126594567674772704813505495154454941","331615822010715899394602592257665789011","100346643228567463340340898921821843914","236384179197020838657079760598215301671","39794677271442683324684517694973341795","327312541752857978314861673731860278775","285040118843961941231640330054411336023","81467387843572206062320395096514942657","105489650659542303204420284291480892411","3446961301124516536414517624476845891","83815411365380239799564098470749565228","248638511297517076754993457007710878503","157035496519292754617397200232473558379","27425517993934035441761888103014628958","232709750944205956897203029143271661411","147394977281828138807509398709256353973","206326346578925864669278834448808657007","266087309997254244671263671282077952659","194012424813186087128450110487182615052","207620637920550068803522328143223142518","220015293549839906171571558862085584183","69982411225867825453945739993328667991","43830109880371544238984752102479370894","206001625593611975921648918930303669742","145850916410669285703562723716069114058","50603939883895231835068387831360670265","214727858775192703697489281110173632458","38986076645361470969919693312214851543","238541766233414105693743360662819816418","126990882814717657730516412606977012669","318444921691416156367246125284994064530","24398493182312861157053486170346419902","157353620633148262010005651451425037774","259112975755528912916766816067545110965","324459218169897020970321051525669162542"],"threshold":0.9},"id":"CVE-2026-12185-34b19082","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d","target":{"file":"prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java","function":"decodeCertificate"},"deprecated":false,"digest":{"function_hash":"288054803277113755444666547869048928941","length":472},"id":"CVE-2026-12185-35f827ef"},{"signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d","target":{"file":"prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java","function":"getObject"},"deprecated":false,"digest":{"function_hash":"178481082840581420363490896444777263761","length":1845},"id":"CVE-2026-12185-476e03b1","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"325918687402241025935941627147437471908","length":1081},"id":"CVE-2026-12185-56bfbda5","signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d","target":{"file":"prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java","function":"decodeKey"}},{"id":"CVE-2026-12185-70db9d88","signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d","target":{"file":"prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java","function":"loadStore"},"deprecated":false,"digest":{"function_hash":"29130605252179874172200646964167497707","length":957}},{"id":"CVE-2026-12185-7bb82e81","signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d","target":{"function":"performTest","file":"prov/src/test/java/org/bouncycastle/jce/provider/test/KeyStoreTest.java"},"deprecated":false,"digest":{"length":157,"function_hash":"158242375678900513393310030637263696831"}},{"id":"CVE-2026-12185-841418f5","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d","target":{"file":"prov/src/test/java/org/bouncycastle/jce/provider/test/KeyStoreTest.java"},"deprecated":false,"digest":{"line_hashes":["84790311362871545751676743701834679534","170509305370039780630652044377074826619","21851042340318058375125050851466058155","75766635981602846335404847046623381326","198973130602544048547144610590315238724","23604481230147967014338401193362755677","211200897897925536299229468707483164068"],"threshold":0.9}},{"deprecated":false,"digest":{"function_hash":"204655545377153142160076523593676393542","length":1212},"id":"CVE-2026-12185-d49db09c","signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d","target":{"file":"prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java","function":"engineLoad"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber"}]}