VendorsBouncy Castlebouncy_castle_for_java_ltsany version
Vulnerabilities

Bouncy Castle Bouncy Castle For Java Lts any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2026-8763
Name Constraints bypass via trailing dot in rfc822Name and URI
Published 2026-08-03 · Analyzed
9.3EPSS 0.005
CVE-2026-59650
MTI/A0 DH agreement exponentiates unvalidated peer value
Published 2026-08-03 · Analyzed
9.3EPSS 0.004
CVE-2026-59638
JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
Published 2026-08-03 · Analyzed
9.3EPSS 0.003
CVE-2026-58062
Stapled OCSP response accepted without binding to the checked certificate
Published 2026-08-03 · Analyzed
9.3EPSS 0.003
CVE-2026-59646
DTLS handshake reassembler allocates buffer from unchecked 24-bit length
Published 2026-08-03 · Analyzed
8.7EPSS 0.006
CVE-2026-58060
HSS public-key level count unbounded, enabling huge allocation on verify
Published 2026-08-03 · Analyzed
8.7EPSS 0.006
CVE-2026-59645
OER parser recurses without depth limit on self-referential IEEE 1609.2 schema
Published 2026-08-03 · Analyzed
8.7EPSS 0.005
CVE-2026-58059
Quadratic-time escaping when stringifying X.500 distinguished names
Published 2026-08-03 · Analyzed
8.7EPSS 0.005
CVE-2026-59649
OpenPGP user-attribute subpacket length bounded only by JVM max memory
Published 2026-08-03 · Analyzed
8.7EPSS 0.005
CVE-2026-13506
Lazy ASN.1 sequence forcing resets nesting-depth guard
Published 2026-08-03 · Analyzed
8.7EPSS 0.004
CVE-2026-59640
OpenPGP CFB quick-check oracle active on symmetric/session-key paths
Published 2026-08-03 · Analyzed
8.7EPSS 0.003
CVE-2026-14682
Possible OOM from unbounded up-front allocation on a definite-length read
Published 2026-08-03 · Analyzed
8.7EPSS 0.003
CVE-2026-59639
CMS verifySignatures returns true for SignedData with zero signers
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-58061
CCM-family modes write plaintext to caller buffer before tag check
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-59641
S/MIME validator trusts signer-asserted signingTime for path validation
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-12803
KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-59642
CMS AuthenticatedData content not bound to MAC when authAttrs present
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-12816
IESEngine stream-mode MAC forgery via length-dependent KDF split
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-12860
RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-12817
OpenPGP AEAD decryption skips final tag on chunk-aligned data
Published 2026-08-03 · Analyzed
8.7EPSS 0.002
CVE-2026-12802
CMS AuthEnvelopedData fails to enforce tag-length on decryption
Published 2026-08-03 · Analyzed
8.7EPSS 0.001
CVE-2026-12185
BKS/UBER keystore allocates from untrusted lengths before integrity check
Published 2026-08-03 · Undergoing Analysis
8.6EPSS 0.003
CVE-2026-15055
PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input
Published 2026-08-03 · Analyzed
8.2EPSS 0.003
CVE-2026-13586
PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)
Published 2026-08-03 · Analyzed
7.5EPSS 0.004
CVE-2026-59651
BKS keystore accepts legacy version with 16-bit integrity MAC key
Published 2026-08-03 · Analyzed
7.5EPSS 0.002
CVE-2026-59647
CRMF/CMP password-MAC honours unbounded iteration count
Published 2026-08-03 · Analyzed
6.9EPSS 0.004
CVE-2026-59648
OpenPGP Argon2 S2K honours attacker-chosen memory and passes
Published 2026-08-03 · Analyzed
6.9EPSS 0.004
CVE-2026-58063
BCFKS keystore load honours unbounded KDF cost from untrusted file
Published 2026-08-03 · Analyzed
5.3EPSS 0.004