Legion of the Bouncy Castle Inc.
- Products in analyzed data
- 12
- Catalog vulnerabilities
- 48
Severity across 48 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 48 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, Legion of the Bouncy Castle Inc. recorded 36 security vulnerabilities in the last 90 days across 4 products, including 29 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, BC-JAVA had the most security vulnerabilities in the Legion of the Bouncy Castle Inc. ecosystem, with 33 vulnerabilities—approximately 91.67% of the provider's total vulnerabilities during this period.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-13505Zeroisation of sensitive key material on garbage collection relies on finalization | Exploitation statusNot known exploited | FixYes | Affected productBC-FJA | Published08/08/2026 | SeverityHigh |
CVE-2026-8798Native entropy source retries the CPU entropy instructions without limit | Exploitation statusNot known exploited | FixYes | Affected productBC-FJA | Published08/08/2026 | SeverityHigh |
CVE-2026-13586PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityMedium |
CVE-2026-13506Lazy ASN.1 sequence forcing resets nesting-depth guard | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-12860RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-12852MLS wire decoder allocates attacker-declared opaque length before bounds check | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-12817OpenPGP AEAD decryption skips final tag on chunk-aligned data | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-12816IESEngine stream-mode MAC forgery via length-dependent KDF split | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-12803KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-12802CMS AuthEnvelopedData fails to enforce tag-length on decryption | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-14682Possible OOM from unbounded up-front allocation on a definite-length read | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-58059Quadratic-time escaping when stringifying X.500 distinguished names | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-58060HSS public-key level count unbounded, enabling huge allocation on verify | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-58061CCM-family modes write plaintext to caller buffer before tag check | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-58062Stapled OCSP response accepted without binding to the checked certificate | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityCritical |
CVE-2026-58063BCFKS keystore load honours unbounded KDF cost from untrusted file | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityMedium |
CVE-2026-59638JSSE hostname verifier CN-fallback enabled by default despite documented opt-in | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityCritical |
CVE-2026-59639CMS verifySignatures returns true for SignedData with zero signers | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-59640OpenPGP CFB quick-check oracle active on symmetric/session-key paths | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-59641S/MIME validator trusts signer-asserted signingTime for path validation | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-59642CMS AuthenticatedData content not bound to MAC when authAttrs present | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-59643OpenPGP inline-signature policy failures silently ignored | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-59644MLS hash-ratchet honours arbitrary 32-bit generation counter from sender | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-59645OER parser recurses without depth limit on self-referential IEEE 1609.2 schema | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-59646DTLS handshake reassembler allocates buffer from unchecked 24-bit length | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-59647CRMF/CMP password-MAC honours unbounded iteration count | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityMedium |
CVE-2026-59648OpenPGP Argon2 S2K honours attacker-chosen memory and passes | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityMedium |
CVE-2026-59649OpenPGP user-attribute subpacket length bounded only by JVM max memory | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-59650MTI/A0 DH agreement exponentiates unvalidated peer value | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityCritical |
CVE-2026-59651BKS keystore accepts legacy version with 16-bit integrity MAC key | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-59652LDAP filter injection in legacy jdk1.4 LDAPStoreHelper | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityMedium |
CVE-2026-12185BKS/UBER keystore allocates from untrusted lengths before integrity check | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityHigh |
CVE-2026-8763Name Constraints bypass via trailing dot in rfc822Name and URI | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityCritical |
CVE-2026-15055PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published08/03/2026 | SeverityMedium |
CVE-2024-14041ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash) | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published07/28/2026 | SeverityHigh |
CVE-2026-15997Native ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow in a crafted encoded state | Exploitation statusNot known exploited | FixYes | Affected productBC-LTS | Published07/16/2026 | SeverityLow |
CVE-2026-8149GCM chunking can lead to bad tag exception on decryption | Exploitation statusNot known exploited | FixYes | Affected productBC-LTS | Published05/08/2026 | SeverityMedium |
CVE-2026-3505Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion. | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published04/15/2026 | SeverityHigh |
CVE-2026-5588PKIX draft CompositeVerifier accepts empty signature sequence as valid. | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published04/15/2026 | SeverityMedium |
CVE-2026-5598Non-constant time comparisons risk private key leakage in FrodoKEM. | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published04/15/2026 | SeverityHigh |
CVE-2026-0636LDAP Injection Vulnerability in LDAPStoreHelper.java | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published04/15/2026 | SeverityMedium |
CVE-2025-14813GOSTCTR implementation unable to process more than 255 blocks correctly | Exploitation statusNot known exploited | FixYes | Affected productBC-JAVA | Published04/15/2026 | SeverityCritical |
CVE-2025-12194CVE-2025-12194 | Exploitation statusNot known exploited | FixYes | Affected productBouncy Castle for Java FIPS | Published10/24/2025 | SeverityMedium |
CVE-2025-9340native encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output. | Exploitation statusNot known exploited | FixYes | Affected productBouncy Castle for Java | Published08/22/2025 | SeverityInformational |
CVE-2025-9341Garbage collection can delay for AES CBC Native support, resulting in heap exhaustion | Exploitation statusNot known exploited | FixYes | Affected productBouncy Castle for Java FIPS | Published08/22/2025 | SeverityMedium |
CVE-2025-9092Hybrid Module Deployment in Multi-JVM Environments Leading to Resource Exhaustion | Exploitation statusNot known exploited | FixYes | Affected productBouncy Castle for Java - BC-FJA 2.1.0 | Published08/16/2025 | SeverityLow |
CVE-2025-8916Possible DOS in processing large name constraint structures in PKIXCertPathReveiwer | Exploitation statusNot known exploited | FixYes | Affected productBC Java | Published08/13/2025 | SeverityMedium |
CVE-2025-8885Possible DOS in processing specially formed ASN.1 Object Identifiers | Exploitation statusNot known exploited | FixYes | Affected productBC Java | Published08/12/2025 | SeverityMedium |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan