CVE-2026-71891
- EPSS 0.17%
- Veröffentlicht 03.10.2026 08:56:01
- Zuletzt bearbeitet 06.10.2026 14:49:40
In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it, accepted a public key built on a forei...
CVE-2026-18040
- EPSS 0.11%
- Veröffentlicht 03.10.2026 08:55:06
- Zuletzt bearbeitet 06.10.2026 14:49:40
In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a function of the operand, and its fixed-weight suppor...
CVE-2026-13586
- EPSS 0.29%
- Veröffentlicht 03.08.2026 02:58:00
- Zuletzt bearbeitet 28.08.2026 16:43:42
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), ...
CVE-2026-13506
- EPSS 0.26%
- Veröffentlicht 03.08.2026 02:56:49
- Zuletzt bearbeitet 28.08.2026 16:41:22
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2...
CVE-2026-12860
- EPSS 0.17%
- Veröffentlicht 03.08.2026 02:55:58
- Zuletzt bearbeitet 28.08.2026 16:35:56
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CVE-2026-12852
- EPSS 0.26%
- Veröffentlicht 03.08.2026 02:55:02
- Zuletzt bearbeitet 28.08.2026 16:16:19
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
CVE-2026-12817
- EPSS 0.16%
- Veröffentlicht 03.08.2026 02:54:16
- Zuletzt bearbeitet 31.08.2026 15:16:42
In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), ...
CVE-2026-12816
- EPSS 0.16%
- Veröffentlicht 03.08.2026 02:53:32
- Zuletzt bearbeitet 02.09.2026 14:38:23
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CVE-2026-12803
- EPSS 0.17%
- Veröffentlicht 03.08.2026 02:52:20
- Zuletzt bearbeitet 02.09.2026 14:37:53
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CVE-2026-12802
- EPSS 0.17%
- Veröffentlicht 03.08.2026 02:48:42
- Zuletzt bearbeitet 02.09.2026 14:37:01
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X serie...