Bouncycastle

Bc-java

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 03.08.2026 00:53:28
  • Zuletzt bearbeitet 28.08.2026 18:12:17

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X...

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 00:51:55
  • Zuletzt bearbeitet 10.09.2026 19:02:52

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:50:50
  • Zuletzt bearbeitet 31.08.2026 18:07:11

In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:49:41
  • Zuletzt bearbeitet 28.08.2026 19:58:41

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0....

  • EPSS 0.29%
  • Veröffentlicht 03.08.2026 00:48:29
  • Zuletzt bearbeitet 28.08.2026 19:57:57

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0...

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:46:57
  • Zuletzt bearbeitet 28.08.2026 19:50:41

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0....

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:45:34
  • Zuletzt bearbeitet 28.08.2026 19:40:16

In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2...

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:44:24
  • Zuletzt bearbeitet 02.09.2026 14:26:57

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X ...

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:42:46
  • Zuletzt bearbeitet 31.08.2026 18:07:14

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 00:41:23
  • Zuletzt bearbeitet 02.09.2026 14:24:53

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.