Bouncycastle / BC-Java
53 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-13586 | PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) | MEDIUM | 5.3 | Aug 3, 2026 |
| CVE-2026-13506 | Lazy ASN.1 sequence forcing resets nesting-depth guard | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-12860 | RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-12852 | MLS wire decoder allocates attacker-declared opaque length before bounds check | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-12817 | OpenPGP AEAD decryption skips final tag on chunk-aligned data | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-12816 | IESEngine stream-mode MAC forgery via length-dependent KDF split | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-12803 | KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-12802 | CMS AuthEnvelopedData fails to enforce tag-length on decryption | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-14682 | Possible OOM from unbounded up-front allocation on a definite-length read | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-58059 | Quadratic-time escaping when stringifying X.500 distinguished names | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-58060 | HSS public-key level count unbounded, enabling huge allocation on verify | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-58061 | CCM-family modes write plaintext to caller buffer before tag check | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-58062 | Stapled OCSP response accepted without binding to the checked certificate | CRITICAL | 9.3 | Aug 3, 2026 |
| CVE-2026-58063 | BCFKS keystore load honours unbounded KDF cost from untrusted file | MEDIUM | 5.3 | Aug 3, 2026 |
| CVE-2026-59638 | JSSE hostname verifier CN-fallback enabled by default despite documented opt-in | CRITICAL | 9.3 | Aug 3, 2026 |
| CVE-2026-59639 | CMS verifySignatures returns true for SignedData with zero signers | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-59640 | OpenPGP CFB quick-check oracle active on symmetric/session-key paths | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-59641 | S/MIME validator trusts signer-asserted signingTime for path validation | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-59642 | CMS AuthenticatedData content not bound to MAC when authAttrs present | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-59643 | OpenPGP inline-signature policy failures silently ignored | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-59644 | MLS hash-ratchet honours arbitrary 32-bit generation counter from sender | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-59645 | OER parser recurses without depth limit on self-referential IEEE 1609.2 schema | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-59646 | DTLS handshake reassembler allocates buffer from unchecked 24-bit length | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-59647 | CRMF/CMP password-MAC honours unbounded iteration count | MEDIUM | 6.9 | Aug 3, 2026 |
| CVE-2026-59648 | OpenPGP Argon2 S2K honours attacker-chosen memory and passes | MEDIUM | 6.9 | Aug 3, 2026 |
Showing 1 to 25 of 53 CVEs