Bouncycastle

Bouncy Castle For Java Lts

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 03.08.2026 02:36:36
  • Zuletzt bearbeitet 02.09.2026 14:32:48

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X serie...

  • EPSS 0.2%
  • Veröffentlicht 03.08.2026 02:35:28
  • Zuletzt bearbeitet 02.09.2026 14:33:49

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X ...

  • EPSS 0.33%
  • Veröffentlicht 03.08.2026 02:29:09
  • Zuletzt bearbeitet 02.09.2026 14:34:30

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X serie...

  • EPSS 0.28%
  • Veröffentlicht 03.08.2026 00:57:31
  • Zuletzt bearbeitet 28.08.2026 17:29:17

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0....

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 00:56:24
  • Zuletzt bearbeitet 28.08.2026 15:33:16

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X se...

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:55:19
  • Zuletzt bearbeitet 28.08.2026 15:40:23

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X se...

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 00:54:21
  • Zuletzt bearbeitet 28.08.2026 18:09:14

In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail...

  • EPSS 0.16%
  • Veröffentlicht 03.08.2026 00:53:28
  • Zuletzt bearbeitet 28.08.2026 18:12:17

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X...

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 00:49:41
  • Zuletzt bearbeitet 28.08.2026 19:58:41

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0....

  • EPSS 0.29%
  • Veröffentlicht 03.08.2026 00:48:29
  • Zuletzt bearbeitet 28.08.2026 19:57:57

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0...