CVE-2026-18040

CVE-2026-18040 published: In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a function of the operand, and its fixed-weight support sampl...

View full NVD advisory → ← Back to CVE watch