Bouncycastle

Bouncy Castle For Java Lts

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 03.08.2026 02:58:00
  • Zuletzt bearbeitet 28.08.2026 16:43:42

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), ...

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 02:56:49
  • Zuletzt bearbeitet 28.08.2026 16:41:22

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2...

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 02:55:58
  • Zuletzt bearbeitet 28.08.2026 16:35:56

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

  • EPSS 0.16%
  • Veröffentlicht 03.08.2026 02:54:16
  • Zuletzt bearbeitet 31.08.2026 15:16:42

In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), ...

  • EPSS 0.16%
  • Veröffentlicht 03.08.2026 02:53:32
  • Zuletzt bearbeitet 02.09.2026 14:38:23

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 02:52:20
  • Zuletzt bearbeitet 02.09.2026 14:37:53

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 02:48:42
  • Zuletzt bearbeitet 02.09.2026 14:37:01

In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X serie...

Medienbericht
  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 02:44:13
  • Zuletzt bearbeitet 28.08.2026 16:44:47

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0....

  • EPSS 0.33%
  • Veröffentlicht 03.08.2026 02:41:30
  • Zuletzt bearbeitet 02.09.2026 14:31:10

In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X seri...

  • EPSS 0.37%
  • Veröffentlicht 03.08.2026 02:37:43
  • Zuletzt bearbeitet 02.09.2026 14:32:13

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X s...