CVE-2026-14682
- EPSS 0.26%
- Veröffentlicht 03.08.2026 02:44:13
- Zuletzt bearbeitet 28.08.2026 16:44:47
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0....
CVE-2026-58059
- EPSS 0.33%
- Veröffentlicht 03.08.2026 02:41:30
- Zuletzt bearbeitet 02.09.2026 14:31:10
In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X seri...
CVE-2026-58060
- EPSS 0.37%
- Veröffentlicht 03.08.2026 02:37:43
- Zuletzt bearbeitet 02.09.2026 14:32:13
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X s...
CVE-2026-58061
- EPSS 0.21%
- Veröffentlicht 03.08.2026 02:36:36
- Zuletzt bearbeitet 02.09.2026 14:32:48
In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X serie...
CVE-2026-58062
- EPSS 0.2%
- Veröffentlicht 03.08.2026 02:35:28
- Zuletzt bearbeitet 02.09.2026 14:33:49
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X ...
CVE-2026-58063
- EPSS 0.33%
- Veröffentlicht 03.08.2026 02:29:09
- Zuletzt bearbeitet 02.09.2026 14:34:30
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X serie...
CVE-2026-59638
- EPSS 0.28%
- Veröffentlicht 03.08.2026 00:57:31
- Zuletzt bearbeitet 28.08.2026 17:29:17
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0....
CVE-2026-59639
- EPSS 0.17%
- Veröffentlicht 03.08.2026 00:56:24
- Zuletzt bearbeitet 28.08.2026 15:33:16
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X se...
CVE-2026-59640
- EPSS 0.26%
- Veröffentlicht 03.08.2026 00:55:19
- Zuletzt bearbeitet 28.08.2026 15:40:23
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X se...
CVE-2026-59641
- EPSS 0.17%
- Veröffentlicht 03.08.2026 00:54:21
- Zuletzt bearbeitet 28.08.2026 18:09:14
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail...