Bouncycastle / Fips Java Api
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-13586 | PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) | MEDIUM | 5.3 | Aug 3, 2026 |
| CVE-2026-13506 | Lazy ASN.1 sequence forcing resets nesting-depth guard | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-14682 | Possible OOM from unbounded up-front allocation on a definite-length read | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-58059 | Quadratic-time escaping when stringifying X.500 distinguished names | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-58060 | HSS public-key level count unbounded, enabling huge allocation on verify | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-58061 | CCM-family modes write plaintext to caller buffer before tag check | HIGH | 8.7 | Aug 3, 2026 |
| CVE-2026-58062 | Stapled OCSP response accepted without binding to the checked certificate | CRITICAL | 9.3 | Aug 3, 2026 |
| CVE-2026-58063 | BCFKS keystore load honours unbounded KDF cost from untrusted file | MEDIUM | 5.3 | Aug 3, 2026 |
| CVE-2026-8763 | Name Constraints bypass via trailing dot in rfc822Name and URI | CRITICAL | 9.3 | Aug 3, 2026 |
| CVE-2023-33202 | bc-java: Out of memory while parsing ASN.1 crafted data in org.bouncycastle.openssl.PEMParser class | MEDIUM | 5.5 | Nov 23, 2023 |
| CVE-2022-45146 | bouncy-castle: Improper Authentication | MEDIUM | 5.5 | Nov 21, 2022 |
| CVE-2020-15522 | bouncycastle: Timing issue within the EC math library | MEDIUM | 5.9 | May 20, 2021 |
| CVE-2020-26939 | In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observa… | MEDIUM | 5.3 | Nov 2, 2020 |
| CVE-2018-1000180 | bouncycastle: flaw in the low-level interface to RSA key pair generator | HIGH | 7.5 | Jun 5, 2018 |
Showing 1 to 14 of 14 CVEs