cbcvebase.

Legion Of The Bouncy Castle Inc Bc-Java vulnerabilities

38 known vulnerabilities affecting legion_of_the_bouncy_castle_inc/bc-java.

Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH25MEDIUM10

Vulnerabilities

Page 1 of 2
CVE-2026-8763P3CRITICALCVSS 9.1fixed in 1.852026-08-03
CVE-2026-8763 [CRITICAL] CWE-295 CVE-2026-8763: In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and UR In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-58062P3CRITICALCVSS 9.1≥ 1.66, < 1.852026-08-03
CVE-2026-58062 [CRITICAL] CWE-295 CVE-2026-58062: In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-59650P3CRITICALCVSS 9.1fixed in 1.852026-08-03
CVE-2026-59650 [CRITICAL] CWE-20 CVE-2026-59650: In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. Thi In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2026-12817P3HIGHCVSS 8.6≥ 1.74, < 1.852026-08-03
CVE-2026-12817 [HIGH] CWE-354 CVE-2026-12817: In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
nvd
CVE-2026-12185P3HIGHCVSS 8.6fixed in 1.852026-08-03
CVE-2026-12185 [HIGH] CWE-789 CVE-2026-12185: In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before int In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2026-5588P3HIGHCVSS 7.5≥ 1.67, < 1.80.2≥ 1.81, < 1.81.1+1 more2026-04-15
CVE-2026-5588 [HIGH] CWE-327 CVE-2026-5588: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. B Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifie
nvd
CVE-2026-5598P3HIGHCVSS 7.5≥ 1.71, < 1.80.2≥ 1.81, < 1.81.1+1 more2026-04-15
CVE-2026-5598 [HIGH] CWE-385 CVE-2026-5598: Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core mo Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
nvd
CVE-2025-14813P3HIGHCVSS 7.5≥ 1.59, < 1.80.2≥ 1.81, < 1.81.1+1 more2026-04-15
CVE-2025-14813 [HIGH] CWE-327 CVE-2025-14813: : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
nvd
CVE-2026-15055P3HIGHCVSS 8.2fixed in 1.852026-08-03
CVE-2026-15055 [HIGH] CWE-770 CVE-2026-15055: In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from inpu In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
nvd
CVE-2026-58061P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-58061 [HIGH] CWE-354 CVE-2026-58061: In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-3505P3HIGHCVSS 7.5≥ 1.74, < 1.80.2≥ 1.81, < 1.81.1+1 more2026-04-15
CVE-2026-3505 [HIGH] CWE-400 CVE-2026-3505: Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerabilit Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java. This issue affects BC-JAVA: from 1.74 before 1.8
nvd
CVE-2026-58060P3HIGHCVSS 7.5≥ 1.65, < 1.852026-08-03
CVE-2026-58060 [HIGH] CWE-789 CVE-2026-58060: In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocatio In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-59649P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59649 [HIGH] CWE-789 CVE-2026-59649: In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM m In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
nvd
CVE-2026-58059P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-58059 [HIGH] CWE-407 CVE-2026-58059: In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-59651P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59651 [HIGH] CWE-326 CVE-2026-59651: In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2026-13506P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-13506 [HIGH] CWE-674 CVE-2026-13506: In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-14682P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-14682 [HIGH] CWE-789 CVE-2026-14682: In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
nvd
CVE-2026-12803P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-12803 [HIGH] CWE-354 CVE-2026-12803: In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (c In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2026-59639P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59639 [HIGH] CWE-347 CVE-2026-59639: In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero si In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
nvd
CVE-2026-59642P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59642 [HIGH] CWE-354 CVE-2026-59642: In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
nvd
Legion Of The Bouncy Castle Inc Bc-Java vulnerabilities | cvebase