Legion Of The Bouncy Castle Inc Bc-Java vulnerabilities
38 known vulnerabilities affecting legion_of_the_bouncy_castle_inc/bc-java.
Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH25MEDIUM10
Vulnerabilities
Page 2 of 2
CVE-2026-12802P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-12802 [HIGH] CWE-354 CVE-2026-12802: In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decrypti
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
nvd
CVE-2026-13586P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-13586 [HIGH] CWE-770 CVE-2026-13586: In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-59646P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-59646 [HIGH] CWE-789 CVE-2026-59646: In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24
In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).
nvd
CVE-2026-59645P3HIGHCVSS 7.5≥ 1.70, < 1.852026-08-03
CVE-2026-59645 [HIGH] CWE-674 CVE-2026-59645: In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential I
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
nvd
CVE-2026-12816P3HIGHCVSS 7.5fixed in 1.852026-08-03
CVE-2026-12816 [HIGH] CWE-354 CVE-2026-12816: In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF sp
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
CVE-2026-12852P3HIGHCVSS 7.5≥ 1.73, < 1.852026-08-03
CVE-2026-12852 [HIGH] CWE-789 CVE-2026-12852: In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length be
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
nvd
CVE-2026-59644P3HIGHCVSS 7.5≥ 1.73, < 1.852026-08-03
CVE-2026-59644 [HIGH] CWE-834 CVE-2026-59644: In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter
In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.
nvd
CVE-2026-59643P3HIGHCVSS 7.5≥ 1.81, < 1.852026-08-03
CVE-2026-59643 [HIGH] CWE-347 CVE-2026-59643: In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. Th
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.
nvd
CVE-2026-0636P3MEDIUMCVSS 6.5≥ 1.74, < 1.80.2≥ 1.81, < 1.81.1+1 more2026-04-15
CVE-2026-0636 [MEDIUM] CWE-90 CVE-2026-0636: Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability i
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).
This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
nvd
CVE-2026-59652P3MEDIUMCVSS 6.5fixed in 1.852026-08-03
CVE-2026-59652 [MEDIUM] CWE-90 CVE-2026-59652: In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
nvd
CVE-2026-59638P3MEDIUMCVSS 6.5≥ 1.61, < 1.852026-08-03
CVE-2026-59638 [MEDIUM] CWE-297 CVE-2026-59638: In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).
nvd
CVE-2024-14041P3MEDIUMCVSS 5.9≥ 1.73, < 1.782026-07-28
CVE-2024-14041 [MEDIUM] CWE-208 CVE-2024-14041: In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided s
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of
nvd
CVE-2026-58063P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-58063 [MEDIUM] CWE-770 CVE-2026-58063: In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
nvd
CVE-2026-59648P4MEDIUMCVSS 5.3≥ 1.71, < 1.852026-08-03
CVE-2026-59648 [MEDIUM] CWE-770 CVE-2026-59648: In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes.
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
nvd
CVE-2026-59647P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-59647 [MEDIUM] CWE-770 CVE-2026-59647: In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
nvd
CVE-2026-59640P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-59640 [MEDIUM] CWE-203 CVE-2026-59640: In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-ke
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
nvd
CVE-2026-59641P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-59641 [MEDIUM] CWE-345 CVE-2026-59641: In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
nvd
CVE-2026-12860P4MEDIUMCVSS 5.3fixed in 1.852026-08-03
CVE-2026-12860 [MEDIUM] CWE-347 CVE-2026-12860: In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omi
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
nvd
← Previous2 / 2