cbcvebase.

Bouncycastle Bc-Java vulnerabilities

52 known vulnerabilities affecting bouncycastle/bc-java.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH29MEDIUM17LOW1

Vulnerabilities

Page 3 of 3
CVE-2026-58063P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-58063 [MEDIUM] CWE-770 CVE-2026-58063: In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-59648P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-59648 [MEDIUM] CWE-770 CVE-2026-59648: In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
nvd
CVE-2023-33201P4MEDIUMCVSS 5.3fixed in 1.742023-07-05
CVE-2023-33201 [MEDIUM] CWE-295 CVE-2023-33201: Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, w
nvd
CVE-2026-59647P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-59647 [MEDIUM] CWE-770 CVE-2026-59647: In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
nvd
CVE-2026-59640P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-59640 [MEDIUM] CWE-203 CVE-2026-59640: In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-ke In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
nvd
CVE-2026-59641P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-59641 [MEDIUM] CWE-345 CVE-2026-59641: In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
nvd
CVE-2016-1000339P4MEDIUMCVSS 5.3≤ 1.552018-06-04
CVE-2016-1000339 [MEDIUM] CWE-310 CVE-2016-1000339: In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also
nvd
CVE-2026-12860P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-12860 [MEDIUM] CWE-347 CVE-2026-12860: In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omi In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2016-2427P4MEDIUMCVSS 5.5v1.542016-04-18
CVE-2016-2427 [MEDIUM] CWE-200 CVE-2016-2427: The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat a cryptographic protection mechanism and discover an authentication key via a crafted application, aka internal bug 26234568. NOTE: The vendor disputes the existence of this p
nvd
CVE-2013-1624P4MEDIUMCVSS 4.0v1.01v1.02+45 more2013-02-08
CVE-2013-1624 [MEDIUM] CVE-2013-1624: The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of tim
nvd
CVE-2018-5382P4MEDIUMCVSS 4.4≤ 1.492018-04-16
CVE-2018-5382 [MEDIUM] CWE-327 CVE-2018-5382: The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compr The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bit HMAC instead. This applies to any BKS keystore generated prior to BC 1.47. For situations where people need to create the files for
nvd
CVE-2016-1000346P4LOWCVSS 3.7≤ 1.552018-06-04
CVE-2016-1000346 [LOW] CWE-320 CVE-2016-1000346: In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not full In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.
nvd
Bouncycastle Bc-Java vulnerabilities | cvebase