CVE-2026-8149 PUBLISHED

GCM chunking can lead to bad tag exception on decryption

Assigner: bcorg
Reserved: 08.05.2026 Published: 08.05.2026 Updated: 08.05.2026

A vulnerability in Legion of the Bouncy Castle Inc. BC-FJA BC-FIPS on Linux, X86_64, AVX, AVX-512f.

This vulnerability is associated with program files gcm128w, gcm512w.

This issue affects BC-FJA: from 2.1.0 through 2.1.2.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/S:N/RE:M/U:Amber
CVSS Score: 5.1

Product Status

Vendor Legion of the Bouncy Castle Inc.
Product BC-FJA
Versions Default: unaffected
  • affected from 2.1.0 to 2.1.2 (incl.)

Workarounds

If possible pass whole message to GCM via doFinal(..) for decryption. Issue only occurs when decryption is chunked at certain boundaries.

Credits

  • Michael Schäfer, Kiteworks finder

References

Problem Types

  • CWE-1068 CWE