Legion of the Bouncy Castle BC-LTS-JAVA

30 known vulnerabilities in Legion of the Bouncy Castle BC-LTS-JAVA, 4 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-97873 CVSS 5.3 medium In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their…
  • CVE-2026-85515 CVSS 8.2 high In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version…
  • CVE-2026-71889 CVSS 8.7 high In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the…
  • CVE-2026-71888 CVSS 8.7 high In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs…
  • CVE-2026-71883 CVSS 8.2 high In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM and GCM-SIV released the…
  • CVE-2026-17508 CVSS 5.3 medium In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the…
  • CVE-2026-14682 CVSS 8.7 high In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects…
  • CVE-2026-13586 CVSS 5.3 medium In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy…
  • CVE-2026-13506 CVSS 8.7 high In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for…
  • CVE-2026-12860 CVSS 8.7 high In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects…
  • CVE-2026-12816 CVSS 8.7 high In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy…
  • CVE-2026-12803 CVSS 8.7 high In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue…
  • CVE-2026-12802 CVSS 8.7 high In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy…
  • CVE-2026-58063 CVSS 5.3 medium In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy…
  • CVE-2026-58062 CVSS 9.3 critical In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects…
  • CVE-2026-58061 CVSS 8.7 high In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy…
  • CVE-2026-58060 CVSS 8.7 high In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects…
  • CVE-2026-58059 CVSS 8.7 high In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy…
  • CVE-2026-8763 CVSS 9.3 critical In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy…
  • CVE-2026-59651 CVSS 7.1 high In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy…
  • CVE-2026-59650 CVSS 9.3 critical In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for…
  • CVE-2026-59648 CVSS 6.9 medium In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle…
  • CVE-2026-59647 CVSS 6.9 medium In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for…
  • CVE-2026-59646 CVSS 8.7 high In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects…
  • CVE-2026-59645 CVSS 8.7 high In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also…
  • CVE-2026-59642 CVSS 8.7 high In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects…
  • CVE-2026-59639 CVSS 8.7 high In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy…
  • CVE-2026-59638 CVSS 9.3 critical In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also…
  • CVE-2026-15055 CVSS 5.3 medium In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy…
  • CVE-2026-12185 CVSS 7.1 high In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects…