Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2024-14041
Legion of the Bouncy Castle Inc. BC-JAVA — ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H P N N H N N 8.2 .0034 25.7 —
AFFECTED
Product Versions Fixed
BC-JAVA 1.73 – —
TIMELINE
Jul 28 Reserved by bcorg
Jul 28 Published (CNA: bcorg)
Aug 26 EXPLOIT PUBLISHED — CVE-2024-14041 (Legion of the Bouncy Castle Inc. BC-JAVA). Public exploit reference added.
Description
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 28, 2026 | Reserved | Reserved by bcorg |
| July 28, 2026 | Published | Published (CNA: bcorg) |
| August 26, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2024-14041 (Legion of the Bouncy Castle Inc. BC-JAVA). Public exploit reference added. |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-14041 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.