Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18040— HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-dependent fixed-weight sampler

Quick assessment

Affected
Legion of the Bouncy Castle Inc. BC-JAVA
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Java 版 Bouncy Castle 1.86 版本之前,HQC 算法通过两个侧信道泄露了由密钥派生的秘密数据:其一,GF(2^8) 算术运算使用了以域元素为索引的查找表,导致被访问的缓存行取决于操作数;其二,固定权重支持采样器在发现碰撞后会立即终止重复扫描,并将接受的密钥位置以秘密索引形式存储。这两种情况在封装和解封装过程中均涉及秘密输入,且采样器在每次解封装时都会从种子重新扩展秘密密钥。因此,攻击者若能观察缓存行为或解封装时间,即可恢复有关 HQC 私钥的信息。现已修复该问题:域算术运算改为无表实现,采

CVSS 5.9 · Medium EPSS 0.11% · P1

Possible ATT&CK Techniques 1 AI

T1040 · Network Sniffing

Affected Version Matrix 1

VendorProduct Version RangeStatus
Legion of the Bouncy Castle Inc. BC-JAVA 1.73< 1.86 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18040

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-dependent fixed-weight sampler
Source: CVE Program / CVE List V5
Vulnerability Description
In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a function of the operand, and its fixed-weight support sampler left its duplicate scan as soon as a collision was found and stored accepted positions at a secret index. Both run on secret inputs during encapsulation and decapsulation, and the sampler re-expands the secret key from its seed on every decapsulation, so an attacker able to observe cache behaviour or decapsulation timing can recover information about the HQC private key. The field arithmetic is now table-free and the sampler branch-free within a batch of candidates, with output and randomness consumption unchanged.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
通过时间差异性导致的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Legion of the Bouncy Castle Inc. BC-JAVA 1.73 ~ 1.86 -

II. Public POCs for CVE-2026-18040

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18040

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-18040 (1)

News Coverage for CVE-2026-18040 (1)

Same Patch Batch · Legion of the Bouncy Castle Inc. · 2026-10-03 · 12 CVEs total

CVE-2026-71885 9.2 CRITICAL MLS X.509 credential not bound to the LeafNode signature key
CVE-2026-71888 8.7 HIGH CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent
CVE-2026-71889 8.7 HIGH PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate
CVE-2026-71890 8.7 HIGH MLS external commit can remove an arbitrary group member
CVE-2026-85515 8.2 HIGH OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check
CVE-2026-71887 8.2 HIGH OpenPGP data signature accepted from a signing subkey without cross-certification
CVE-2026-71883 8.2 HIGH Native AES packet cipher returns the raw AES key on an alias
CVE-2026-71886 8.2 HIGH OpenPGP certification accepted from a subkey without certification authority
CVE-2026-71891 7.1 HIGH BLS12-381 key validation accepts a public key built on a foreign curve
CVE-2026-71892 6.9 MEDIUM CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys
CVE-2026-97873 5.3 MEDIUM Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider

IV. Related Vulnerabilities

V. Comments for CVE-2026-18040

No comments yet


Leave a comment