Bouncycastle

Fips Java Api

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 03.08.2026 02:58:00
  • Zuletzt bearbeitet 28.08.2026 16:43:42

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), ...

  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 02:56:49
  • Zuletzt bearbeitet 28.08.2026 16:41:22

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2...

Medienbericht
  • EPSS 0.26%
  • Veröffentlicht 03.08.2026 02:44:13
  • Zuletzt bearbeitet 28.08.2026 16:44:47

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0....

  • EPSS 0.33%
  • Veröffentlicht 03.08.2026 02:41:30
  • Zuletzt bearbeitet 02.09.2026 14:31:10

In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X seri...

  • EPSS 0.37%
  • Veröffentlicht 03.08.2026 02:37:43
  • Zuletzt bearbeitet 02.09.2026 14:32:13

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X s...

  • EPSS 0.21%
  • Veröffentlicht 03.08.2026 02:36:36
  • Zuletzt bearbeitet 02.09.2026 14:32:48

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X serie...

  • EPSS 0.2%
  • Veröffentlicht 03.08.2026 02:35:28
  • Zuletzt bearbeitet 02.09.2026 14:33:49

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X ...

  • EPSS 0.33%
  • Veröffentlicht 03.08.2026 02:29:09
  • Zuletzt bearbeitet 02.09.2026 14:34:30

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X serie...

  • EPSS 0.33%
  • Veröffentlicht 03.08.2026 00:36:05
  • Zuletzt bearbeitet 02.09.2026 14:28:48

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), ...

Exploit
  • EPSS 0.93%
  • Veröffentlicht 23.11.2023 16:15:07
  • Zuletzt bearbeitet 18.08.2025 17:15:27

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, ...