VendorsBouncy Castlebcpkix-fipsall versions
Vulnerabilities

Bouncy Castle Bcpkix-fips

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-59639
CMS verifySignatures returns true for SignedData with zero signers
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-12802
CMS AuthEnvelopedData fails to enforce tag-length on decryption
Published 2026-08-03 · Analyzed
8.7EPSS 0.001
CVE-2026-59642
CMS AuthenticatedData content not bound to MAC when authAttrs present
Published 2026-08-03 · Analyzed
8.7EPSS 0.001
CVE-2026-15055
PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input
Published 2026-08-03 · Analyzed
8.2EPSS 0.003
CVE-2026-59647
CRMF/CMP password-MAC honours unbounded iteration count
Published 2026-08-03 · Analyzed
6.9EPSS 0.003