VendorsBouncy Castlebcpg-fipsany version
Vulnerabilities

Bouncy Castle Bcpg-fips any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-59649
OpenPGP user-attribute subpacket length bounded only by JVM max memory
Published 2026-08-03 · Analyzed
8.7EPSS 0.005
CVE-2026-59640
OpenPGP CFB quick-check oracle active on symmetric/session-key paths
Published 2026-08-03 · Analyzed
8.7EPSS 0.003
CVE-2026-59643
OpenPGP inline-signature policy failures silently ignored
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-12817
OpenPGP AEAD decryption skips final tag on chunk-aligned data
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-59648
OpenPGP Argon2 S2K honours attacker-chosen memory and passes
Published 2026-08-03 · Analyzed
6.9EPSS 0.004