AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-1000340

HIGH · CVSS 7.5 EPSS 2.26% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-06-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2016-1000340
Severity
HIGH
CVSS
7.5
EPSS
2.26%

Original NVD Description

In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.raw.Nat???). These classes are used by our custom elliptic curve implementations (org.bouncycastle.math.ec.custom.**), so there was the possibility of rare (in general usage) spurious calculations for elliptic curve scalar multiplications. Such errors would have been detected with high probability by the output validation for our scalar multipliers.