Bouncycastle Bc-Java vulnerabilities
52 known vulnerabilities affecting bouncycastle/bc-java.
Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH29MEDIUM17LOW1
Vulnerabilities
Page 2 of 3
CVE-2026-59642P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59642 [HIGH] CWE-354 CVE-2026-59642: In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs
In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
nvd
CVE-2026-12802P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-12802 [HIGH] CWE-354 CVE-2026-12802: In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decrypti
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
nvd
CVE-2026-13586P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-13586 [HIGH] CWE-770 CVE-2026-13586: In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-59646P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59646 [HIGH] CWE-789 CVE-2026-59646: In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24
In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).
nvd
CVE-2026-59645P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59645 [HIGH] CWE-674 CVE-2026-59645: In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential I
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
nvd
CVE-2026-12816P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-12816 [HIGH] CWE-354 CVE-2026-12816: In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF sp
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2016-1000343P3HIGHCVSS 7.5≤ 1.552018-06-04
CVE-2016-1000343 [HIGH] CWE-310 CVE-2016-1000343: In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a we
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by expli
nvd
CVE-2026-12852P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-12852 [HIGH] CWE-789 CVE-2026-12852: In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length be
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
nvd
CVE-2026-59644P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59644 [HIGH] CWE-834 CVE-2026-59644: In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter
In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.
nvd
CVE-2026-59643P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59643 [HIGH] CWE-347 CVE-2026-59643: In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. Th
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.
nvd
CVE-2016-1000344P3HIGHCVSS 7.4≤ 1.552018-06-04
CVE-2016-1000344 [HIGH] CWE-310 CVE-2016-1000344: In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.
nvd
CVE-2016-1000352P3HIGHCVSS 7.4≤ 1.552018-06-04
CVE-2016-1000352 [HIGH] CWE-310 CVE-2016-1000352: In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use
In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.
nvd
CVE-2016-1000342P3HIGHCVSS 7.5≤ 1.552018-06-04
CVE-2016-1000342 [HIGH] CWE-347 CVE-2016-1000342: In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encod
In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.
nvd
CVE-2016-1000340P3HIGHCVSS 7.5≥ 1.51, ≤ 1.552018-06-04
CVE-2016-1000340 [HIGH] CWE-19 CVE-2016-1000340: In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in t
In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.raw.Nat???). These classes are used by our custom elliptic curve implementations (org.bouncycastle.math.ec.custom.**), so there was the possibility of r
nvd
CVE-2007-6721P3CRITICALCVSS 10.0≤ 1.37v1.01+35 more2009-03-30
CVE-2007-6721 [CRITICAL] CVE-2007-6721: The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provide
The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes."
nvd
CVE-2026-59652P3MEDIUMCVSS 6.5fixed in 1.852026-08-03
CVE-2026-59652 [MEDIUM] CWE-90 CVE-2026-59652: In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
nvd
CVE-2026-59638P3MEDIUMCVSS 6.5fixed in 1.852026-08-03
CVE-2026-59638 [MEDIUM] CWE-297 CVE-2026-59638: In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).
nvd
CVE-2024-14041P3MEDIUMCVSS 5.9≥ 1.73, < 1.782026-07-28
CVE-2024-14041 [MEDIUM] CWE-208 CVE-2024-14041: In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided s
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of
nvd
CVE-2016-1000345P4MEDIUMCVSS 5.9≤ 1.552018-06-04
CVE-2016-1000345 [MEDIUM] CWE-361 CVE-2016-1000345: In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to pa
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.
nvd
CVE-2016-1000341P4MEDIUMCVSS 5.9≤ 1.552018-06-04
CVE-2016-1000341 [MEDIUM] CWE-361 CVE-2016-1000341: In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to
In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of blinding in 1.55, or earlier, may allow an attacker to gain information about the signature's k value and ultimately the private value as well.
nvd