Legion of the Bouncy Castle BC-JAVA
43 known vulnerabilities in Legion of the Bouncy Castle BC-JAVA, 6 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-97873 CVSS 5.3 medium In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their…
- CVE-2026-85515 CVSS 8.2 high In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version…
- CVE-2026-71892 CVSS 6.9 medium In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients…
- CVE-2026-71891 CVSS 7.1 high In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme…
- CVE-2026-71890 CVSS 8.7 high In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list…
- CVE-2026-71889 CVSS 8.7 high In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the…
- CVE-2026-71888 CVSS 8.7 high In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs…
- CVE-2026-71887 CVSS 8.2 high In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding…
- CVE-2026-71886 CVSS 8.2 high In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation…
- CVE-2026-71885 CVSS 9.2 critical In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a…
- CVE-2026-18040 CVSS 5.9 medium In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables…
- CVE-2026-18036 CVSS 8.2 high In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are…
- CVE-2026-17508 CVSS 5.3 medium In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the…
- CVE-2026-17507 CVSS 8.7 high In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int…
- CVE-2026-14682 CVSS 8.7 high In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects…
- CVE-2026-13586 CVSS 5.3 medium In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy…
- CVE-2026-13506 CVSS 8.7 high In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for…
- CVE-2026-12860 CVSS 8.7 high In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects…
- CVE-2026-12816 CVSS 8.7 high In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy…
- CVE-2026-12803 CVSS 8.7 high In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue…
- CVE-2026-12802 CVSS 8.7 high In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy…
- CVE-2026-58063 CVSS 5.3 medium In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy…
- CVE-2026-58062 CVSS 9.3 critical In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects…
- CVE-2026-58061 CVSS 8.7 high In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy…
- CVE-2026-58060 CVSS 8.7 high In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects…
- CVE-2026-58059 CVSS 8.7 high In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy…
- CVE-2026-8763 CVSS 9.3 critical In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy…
- CVE-2026-59652 CVSS 6.9 medium In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
- CVE-2026-59651 CVSS 7.1 high In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy…
- CVE-2026-59650 CVSS 9.3 critical In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for…