← Back

Legion Of The Bouncy Castle C# Cryptography Api

legion-of-the-bouncy-castle-c#-cryptography-api

Vendor: Bouncycastle • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bouncycastle
2Bc Java
Legion Of The Bouncy Castle C# Cryptography Api
Apr 29, 2026
Feb 8, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malform...Show more
The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.Show less