CVE-2026-71884 - Packet CTR reports a full success length after the counter is exhausted
CVE ID :CVE-2026-71884 Published : Oct. 9, 2026, 10:16 a.m. | 1 hour, 13 minutes ago Description :In Bouncy Castle for Java LTS before 2.73.13, the native one-shot CTR packet cipher did not check that the requested input length fitted the counter space the IV left. In CTR mode the IV and the...