Bouncycastle

Bcpg-fips

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 03.08.2026 02:54:16
  • Zuletzt bearbeitet 31.08.2026 15:16:42

In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), ...

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:55:19
  • Zuletzt bearbeitet 28.08.2026 15:40:23

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X se...

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 00:51:55
  • Zuletzt bearbeitet 10.09.2026 19:02:52

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:45:34
  • Zuletzt bearbeitet 28.08.2026 19:40:16

In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2...

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:44:24
  • Zuletzt bearbeitet 02.09.2026 14:26:57

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X ...