Vulnerability GHSA-574f-3g2m-x479

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 months ago
April 17, 2026 at 06:31 PM UTC
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
1.59.0 - 1.60.0 and 1.64.0 and 1.68.0 - 1.74.0 and 1.78.0 - 1.83.0
1.59.0 - 1.60.0 and 1.64.0 and 1.68.0 - 1.74.0 and 1.78.0 - 1.83.0

Summary

Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks

Details

The GOST 28147-2015 CTR mode implementation (G3413CTRBlockCipher) in the Legion of the Bouncy Castle BC-JAVA bcprov core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).

References

Timeline

Published
5 months ago
April 17, 2026 at 06:31 PM UTC
Fixed (1.84)
Unknown
Unknown
Fixed (1.84)
Unknown
Unknown
Fixed (1.84)
Unknown
Unknown
Fixed (1.84)
Unknown
Unknown
Fixed (1.84)
Unknown
Unknown
Fixed (1.80.2)
Unknown
Unknown
Fixed (1.81.1)
Unknown
Unknown
Fixed (1.84)
Unknown
Unknown
Last Modified
3 days ago
September 24, 2026 at 03:30 PM UTC