Bouncycastle Bc-Java vulnerabilities
52 known vulnerabilities affecting bouncycastle/bc-java.
Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH29MEDIUM17LOW1
Vulnerabilities
Page 1 of 3
CVE-2020-28052P3HIGHCVSS 8.1v1.65v1.662020-12-18
CVE-2020-28052 [HIGH] CVE-2020-28052: An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.chec
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
nvd
CVE-2018-1000613P3CRITICALCVSS 9.8≥ 1.58, < 1.602018-07-09
CVE-2018-1000613 [CRITICAL] CWE-470 CVE-2018-1000613: Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not in
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result
nvd
CVE-2026-8763P3CRITICALCVSS 9.1fixed in 1.852026-08-03
CVE-2026-8763 [CRITICAL] CWE-295 CVE-2026-8763: In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and UR
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-58062P3CRITICALCVSS 9.1≥ 1.66, < 1.852026-08-03
CVE-2026-58062 [CRITICAL] CWE-295 CVE-2026-58062: In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-59650P3CRITICALCVSS 9.1fixed in 1.852026-08-03
CVE-2026-59650 [CRITICAL] CWE-20 CVE-2026-59650: In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. Thi
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2026-12817P3HIGHCVSS 8.6fixed in 1.852026-08-03
CVE-2026-12817 [HIGH] CWE-354 CVE-2026-12817: In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data
In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
nvd
CVE-2026-12185P3HIGHCVSS 8.6fixed in 1.852026-08-03
CVE-2026-12185 [HIGH] CWE-789 CVE-2026-12185: In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before int
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2017-13098P3MEDIUMCVSS 5.9fixed in 1.592017-12-13
CVE-2017-13098 [MEDIUM] CWE-203 CVE-2017-13098: BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."
nvd
CVE-2026-15055P3HIGHCVSS 8.2fixed in 1.852026-08-03
CVE-2026-15055 [HIGH] CWE-770 CVE-2026-15055: In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from inpu
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
nvd
CVE-2026-58061P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-58061 [HIGH] CWE-354 CVE-2026-58061: In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag
In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2019-17359P3HIGHCVSS 7.5v1.632019-10-08
CVE-2019-17359 [HIGH] CWE-770 CVE-2019-17359: The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory all
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
nvd
CVE-2026-58060P3HIGHCVSS 7.5≥ 1.65, < 1.852026-08-03
CVE-2026-58060 [HIGH] CWE-789 CVE-2026-58060: In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocatio
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-59649P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59649 [HIGH] CWE-789 CVE-2026-59649: In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM m
In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
nvd
CVE-2018-1000180P3HIGHCVSS 7.5≥ 1.54, ≤ 1.592018-06-05
CVE-2018-1000180 [HIGH] CWE-327 CVE-2018-1000180: Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level in
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
nvd
CVE-2026-58059P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-58059 [HIGH] CWE-407 CVE-2026-58059: In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished
In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-59651P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59651 [HIGH] CWE-326 CVE-2026-59651: In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC
In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2026-13506P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-13506 [HIGH] CWE-674 CVE-2026-13506: In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-14682P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-14682 [HIGH] CWE-789 CVE-2026-14682: In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
nvd
CVE-2026-12803P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-12803 [HIGH] CWE-354 CVE-2026-12803: In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (c
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2026-59639P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59639 [HIGH] CWE-347 CVE-2026-59639: In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero si
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
nvd
1 / 3Next →