Covert Timing Channel in Bouncy Castle for Java - CVE-2026-5598
Published: May 25, 2026
Vulnerability identifier: #VU132259
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-5598
CWE-ID: CWE-385
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a covert timing channel in FrodoEngine.java in the BC-JAVA core modules when performing cryptographic operations. A remote attacker can measure timing differences to disclose sensitive information.
Affected software
Bouncy Castle for Java
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Development Tools Module
Fusion Content-Aware Storage
IBM Tivoli Netcool Configuration Manager
IBM Business Automation Manager Open Editions
ApplinX
Data Cataloging
IBM Fusion HCI
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Crucible Data Center
Crucible Server
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
Bitbucket Data Center
Bamboo Data Center
IBM Cloud Object Storage Systems
IBM Qradar SIEM
IBM DB2
IBM App Connect Enterprise
bouncycastle-pkix
bouncycastle-util
bouncycastle-pg
bouncycastle
IBM Disconnected Log Collector
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Development Tools Module
Fusion Content-Aware Storage
IBM Tivoli Netcool Configuration Manager
IBM Business Automation Manager Open Editions
ApplinX
Data Cataloging
IBM Fusion HCI
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Crucible Data Center
Crucible Server
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
Bitbucket Data Center
Bamboo Data Center
IBM Cloud Object Storage Systems
IBM Qradar SIEM
IBM DB2
IBM App Connect Enterprise
bouncycastle-pkix
bouncycastle-util
bouncycastle-pg
bouncycastle
IBM Disconnected Log Collector
How to mitigate CVE-2026-5598
Install security update from vendor's website.
Bouncy Castle for Java - addressed in versions 1.80.1, 1.81.1, 1.84
Fusion Content-Aware Storage - update to 1.1.5
IBM Fusion HCI - update to 2.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4.0 Patch 3
Crucible Data Center - update to 4.9.10
Crucible Server - update to 4.9.10
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
IBM Business Automation Manager Open Editions - update to 8.0.9 IF0002
Bitbucket Data Center - update to 9.4.22
Bamboo Data Center - addressed in versions 10.2.19, 12.1.7
IBM App Connect Enterprise - update to 13.0.8.0
bouncycastle-pkix - update to 1.84-150200.3.35.1
bouncycastle-util - update to 1.84-150200.3.35.1
bouncycastle-pg - update to 1.84-150200.3.35.1
bouncycastle - update to 1.84-150200.3.35.1
IBM Disconnected Log Collector - update to 2.0.1
Data Cataloging - update to 2.5.3
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.91, 3.20.1.84
Fusion Content-Aware Storage - update to 1.1.5
IBM Fusion HCI - update to 2.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4.0 Patch 3
Crucible Data Center - update to 4.9.10
Crucible Server - update to 4.9.10
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
IBM Business Automation Manager Open Editions - update to 8.0.9 IF0002
Bitbucket Data Center - update to 9.4.22
Bamboo Data Center - addressed in versions 10.2.19, 12.1.7
IBM App Connect Enterprise - update to 13.0.8.0
bouncycastle-pkix - update to 1.84-150200.3.35.1
bouncycastle-util - update to 1.84-150200.3.35.1
bouncycastle-pg - update to 1.84-150200.3.35.1
bouncycastle - update to 1.84-150200.3.35.1
IBM Disconnected Log Collector - update to 2.0.1
Data Cataloging - update to 2.5.3
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.91, 3.20.1.84
External References
Related Security Bulletins
- Covert timing channel in The Bouncy Castle Crypto Package For Java
- SUSE update for bouncycastle
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in Bamboo Data Center
- Multiple vulnerabilities in Crucible Data Center and Crucible Server
- Multiple vulnerabilities in IBM Sterling Connect:Direct Web Services
- Multiple vulnerabilities in IBM ApplinX
- Multiple vulnerabilities in IBM Tivoli Netcool Configuration Manager
- Multiple vulnerabilities in IBM Db2
- Multiple vulnerabilities in IBM Fusion, IBM Fusion HCI, IBM Fusion Data Cataloging, and IBM Fusion Content-Aware Storage
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM Cloud Object Storage System
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Multiple vulnerabilities in Bitbucket Data Center
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- Multiple vulnerabilities in IBM Sterling Secure Proxy