Bouncycastle

Bctls-fips

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 02:44:13
  • Zuletzt bearbeitet 28.08.2026 16:44:47

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0....

  • EPSS 0.28%
  • Veröffentlicht 03.08.2026 00:57:31
  • Zuletzt bearbeitet 28.08.2026 17:29:17

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0....

  • EPSS 0.29%
  • Veröffentlicht 03.08.2026 00:48:29
  • Zuletzt bearbeitet 28.08.2026 19:57:57

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0...