An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03
https://cert-portal.siemens.com/productcert/html/ssa-485750.html