Fips Java Api
Bouncycastle · 14 CVEs
PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)
Aug 3, 2026
Lazy ASN.1 sequence forcing resets nesting-depth guard
Aug 3, 2026
Possible OOM from unbounded up-front allocation on a definite-length read
Aug 3, 2026
Quadratic-time escaping when stringifying X.500 distinguished names
Aug 3, 2026
HSS public-key level count unbounded, enabling huge allocation on verify
Aug 3, 2026
CCM-family modes write plaintext to caller buffer before tag check
Aug 3, 2026
Stapled OCSP response accepted without binding to the checked certificate
Aug 3, 2026
BCFKS keystore load honours unbounded KDF cost from untrusted file
Aug 3, 2026
Name Constraints bypass via trailing dot in rfc822Name and URI
Aug 3, 2026
bc-java: Out of memory while parsing ASN.1 crafted data in org.bouncycastle.openssl.PEMParser class
Nov 23, 2023
bouncy-castle: Improper Authentication
Nov 21, 2022
bouncycastle: Timing issue within the EC math library
May 20, 2021
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information abo…
Nov 2, 2020
bouncycastle: flaw in the low-level interface to RSA key pair generator
Jun 5, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-13586 | PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) | MEDIUM | 0.35% | Aug 3, 2026 |
| CVE-2026-13506 | Lazy ASN.1 sequence forcing resets nesting-depth guard | HIGH | 0.44% | Aug 3, 2026 |
| CVE-2026-14682 | Possible OOM from unbounded up-front allocation on a definite-length read | HIGH | 0.33% | Aug 3, 2026 |
| CVE-2026-58059 | Quadratic-time escaping when stringifying X.500 distinguished names | HIGH | 0.49% | Aug 3, 2026 |
| CVE-2026-58060 | HSS public-key level count unbounded, enabling huge allocation on verify | HIGH | 0.62% | Aug 3, 2026 |
| CVE-2026-58061 | CCM-family modes write plaintext to caller buffer before tag check | HIGH | 0.24% | Aug 3, 2026 |
| CVE-2026-58062 | Stapled OCSP response accepted without binding to the checked certificate | CRITICAL | 0.27% | Aug 3, 2026 |
| CVE-2026-58063 | BCFKS keystore load honours unbounded KDF cost from untrusted file | MEDIUM | 0.42% | Aug 3, 2026 |
| CVE-2026-8763 | Name Constraints bypass via trailing dot in rfc822Name and URI | CRITICAL | 0.43% | Aug 3, 2026 |
| CVE-2023-33202 | bc-java: Out of memory while parsing ASN.1 crafted data in org.bouncycastle.openssl.PEMParser class | MEDIUM | 1.02% | Nov 23, 2023 |
| CVE-2022-45146 | bouncy-castle: Improper Authentication | MEDIUM | 0.43% | Nov 21, 2022 |
| CVE-2020-15522 | bouncycastle: Timing issue within the EC math library | MEDIUM | 1.52% | May 20, 2021 |
| CVE-2020-26939 | In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observa… | MEDIUM | 0.92% | Nov 2, 2020 |
| CVE-2018-1000180 | bouncycastle: flaw in the low-level interface to RSA key pair generator | HIGH | 3.58% | Jun 5, 2018 |
Showing 1 to 14 of 14 CVEs