CVE-2026-13586
- EPSS 0.29%
- Veröffentlicht 03.08.2026 02:58:00
- Zuletzt bearbeitet 28.08.2026 16:43:42
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), ...
CVE-2026-13506
- EPSS 0.26%
- Veröffentlicht 03.08.2026 02:56:49
- Zuletzt bearbeitet 28.08.2026 16:41:22
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2...
CVE-2026-12860
- EPSS 0.17%
- Veröffentlicht 03.08.2026 02:55:58
- Zuletzt bearbeitet 28.08.2026 16:35:56
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CVE-2026-12817
- EPSS 0.16%
- Veröffentlicht 03.08.2026 02:54:16
- Zuletzt bearbeitet 31.08.2026 15:16:42
In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), ...
CVE-2026-12816
- EPSS 0.16%
- Veröffentlicht 03.08.2026 02:53:32
- Zuletzt bearbeitet 02.09.2026 14:38:23
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CVE-2026-12803
- EPSS 0.17%
- Veröffentlicht 03.08.2026 02:52:20
- Zuletzt bearbeitet 02.09.2026 14:37:53
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CVE-2026-12802
- EPSS 0.17%
- Veröffentlicht 03.08.2026 02:48:42
- Zuletzt bearbeitet 02.09.2026 14:37:01
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X serie...
CVE-2026-14682
- EPSS 0.26%
- Veröffentlicht 03.08.2026 02:44:13
- Zuletzt bearbeitet 28.08.2026 16:44:47
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0....
CVE-2026-58059
- EPSS 0.33%
- Veröffentlicht 03.08.2026 02:41:30
- Zuletzt bearbeitet 02.09.2026 14:31:10
In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X seri...
CVE-2026-58060
- EPSS 0.37%
- Veröffentlicht 03.08.2026 02:37:43
- Zuletzt bearbeitet 02.09.2026 14:32:13
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X s...