VendorsBouncy Castlefips_java_apiall versions
Vulnerabilities

Bouncy Castle FIPS Java API (BC-FJA)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2026-8763
Name Constraints bypass via trailing dot in rfc822Name and URI
Published 2026-08-03 · Analyzed
9.3EPSS 0.004
CVE-2026-58062
Stapled OCSP response accepted without binding to the checked certificate
Published 2026-08-03 · Analyzed
9.3EPSS 0.003
CVE-2026-58060
HSS public-key level count unbounded, enabling huge allocation on verify
Published 2026-08-03 · Analyzed
8.7EPSS 0.007
CVE-2026-58059
Quadratic-time escaping when stringifying X.500 distinguished names
Published 2026-08-03 · Analyzed
8.7EPSS 0.005
CVE-2026-13506
Lazy ASN.1 sequence forcing resets nesting-depth guard
Published 2026-08-03 · Analyzed
8.7EPSS 0.003
CVE-2026-14682
Possible OOM from unbounded up-front allocation on a definite-length read
Published 2026-08-03 · Analyzed
8.7EPSS 0.003
CVE-2026-58061
CCM-family modes write plaintext to caller buffer before tag check
Published 2026-08-03 · Analyzed
8.7EPSS 0.003
CVE-2018-1000180
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Published 2018-06-05 · Modified
7.5EPSS 0.036
CVE-2026-13586
PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)
Published 2026-08-03 · Analyzed
7.5EPSS 0.004
CVE-2020-15522
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
Published 2021-05-20 · Modified
5.9EPSS 0.015
CVE-2023-33202
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.)
Published 2023-11-23 · Modified
5.5EPSS 0.009
CVE-2022-45146
An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or potential information loss. NOTE: FIPS compliant users are unaffected because the FIPS certification is only for Java 7, 8, and 11.
Published 2022-11-21 · Modified
5.5EPSS 0.004
CVE-2020-26939
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder could result in the throwing of an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.
Published 2020-11-02 · Modified
5.3EPSS 0.009
CVE-2026-58063
BCFKS keystore load honours unbounded KDF cost from untrusted file
Published 2026-08-03 · Analyzed
5.3EPSS 0.004