Bouncycastle Fips Java Api vulnerabilities
14 known vulnerabilities affecting bouncycastle/fips_java_api.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH7MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2026-8763P3CRITICALCVSS 9.1≥ 1.0.0, < 1.0.2.7≥ 2.0.0, < 2.0.2+1 more2026-08-03
CVE-2026-8763 [CRITICAL] CWE-295 CVE-2026-8763: In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and UR
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-58062P3CRITICALCVSS 9.1fixed in 2.0.2≥ 2.1.0, < 2.1.32026-08-03
CVE-2026-58062 [CRITICAL] CWE-295 CVE-2026-58062: In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-58061P3HIGHCVSS 7.5≥ 1.0.0, < 1.0.2.7≥ 2.0.0, < 2.0.2+1 more2026-08-03
CVE-2026-58061 [HIGH] CWE-354 CVE-2026-58061: In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag
In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-58060P3HIGHCVSS 7.5fixed in 2.0.2≥ 2.1.0, < 2.1.32026-08-03
CVE-2026-58060 [HIGH] CWE-789 CVE-2026-58060: In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocatio
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2018-1000180P3HIGHCVSS 7.5≤ 1.0.12018-06-05
CVE-2018-1000180 [HIGH] CWE-327 CVE-2018-1000180: Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level in
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
nvd
CVE-2026-58059P3HIGHCVSS 7.5≥ 1.0.0, < 1.0.2.7≥ 2.0.0, < 2.0.2+1 more2026-08-03
CVE-2026-58059 [HIGH] CWE-407 CVE-2026-58059: In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished
In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-13506P3HIGHCVSS 7.5≥ 1.0.0, < 1.0.2.7≥ 2.0.0, < 2.0.2+1 more2026-08-03
CVE-2026-13506 [HIGH] CWE-674 CVE-2026-13506: In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-14682P3HIGHCVSS 7.5≥ 1.0.0, < 1.0.2.7≥ 2.0.0, < 2.0.2+1 more2026-08-03
CVE-2026-14682 [HIGH] CWE-789 CVE-2026-14682: In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
nvd
CVE-2026-13586P3HIGHCVSS 7.5≥ 1.0.0, < 1.0.2.7≥ 2.0.0, < 2.0.2+1 more2026-08-03
CVE-2026-13586 [HIGH] CWE-770 CVE-2026-13586: In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-58063P4MEDIUMCVSS 5.3≥ 1.0.0, < 1.0.2.7≥ 2.0.0, < 2.0.2+1 more2026-08-03
CVE-2026-58063 [MEDIUM] CWE-770 CVE-2026-58063: In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2020-15522P4MEDIUMCVSS 5.9fixed in 1.0.1.2≥ 1.0.2, < 1.0.2.12021-05-20
CVE-2020-15522 [MEDIUM] CWE-362 CVE-2020-15522: Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-F
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
nvd
CVE-2022-45146P4MEDIUMCVSS 5.5fixed in 1.0.2.42022-11-21
CVE-2022-45146 [MEDIUM] CWE-416 CVE-2022-45146: An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the
An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or potential information loss. NOTE
nvd
CVE-2020-26939P4MEDIUMCVSS 5.3fixed in 1.0.1.22020-11-02
CVE-2020-26939 [MEDIUM] CWE-203 CVE-2020-26939: In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensit
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder coul
nvd
CVE-2023-33202P4MEDIUMCVSS 5.5fixed in 1.0.2.42023-11-23
CVE-2023-33202 [MEDIUM] CWE-400 CVE-2023-33202: Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bou
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMe
nvd