CVE-2026-59652
- EPSS 0.34%
- Veröffentlicht 03.08.2026 00:39:23
- Zuletzt bearbeitet 02.09.2026 14:23:52
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
CVE-2026-12185
- EPSS 0.26%
- Veröffentlicht 03.08.2026 00:38:01
- Zuletzt bearbeitet 28.08.2026 14:42:59
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CVE-2026-8763
- EPSS 0.33%
- Veröffentlicht 03.08.2026 00:36:05
- Zuletzt bearbeitet 02.09.2026 14:28:48
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), ...
CVE-2026-15055
- EPSS 0.26%
- Veröffentlicht 03.08.2026 00:32:51
- Zuletzt bearbeitet 28.08.2026 15:04:27
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series...
CVE-2024-14041
- EPSS 0.28%
- Veröffentlicht 28.07.2026 08:17:12
- Zuletzt bearbeitet 02.10.2026 00:10:00
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly....
CVE-2024-29857
- EPSS 1.1%
- Veröffentlicht 14.05.2024 15:17:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to exc...
CVE-2023-33201
- EPSS 0.77%
- Veröffentlicht 05.07.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:05:06
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bo...
CVE-2020-28052
- EPSS 7.14%
- Veröffentlicht 18.12.2020 01:15:12
- Zuletzt bearbeitet 12.05.2025 17:37:16
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previous...
CVE-2019-17359
- EPSS 8.95%
- Veröffentlicht 08.10.2019 14:15:10
- Zuletzt bearbeitet 12.05.2025 17:37:16
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
CVE-2018-1000613
- EPSS 4.77%
- Veröffentlicht 09.07.2018 20:29:00
- Zuletzt bearbeitet 12.05.2025 17:37:16
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT priv...