CVE-2026-18036 | Legion of the Bouncy Castle BC-JAVA up to 1.85 NTRU Polynomial.modQ/Polynomial.mod3/NTRUSampling.mod3 divisor timing discrepancy

SecurityVulns

A vulnerability marked as problematic has been reported in Legion of the Bouncy Castle BC-JAVA up to 1.85. This affects the function Polynomial.modQ/Polynomial.mod3/NTRUSampling.mod3 of the component NTRU. The manipulation of the argument divisor leads to observable timing discrepancy.

This vulnerability is uniquely identified as CVE-2026-18036. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More