LIVE · cybersecurity feed
Live wire
vendor

Bouncycastle

23 CVEs published in the last four months. Exploited flaws first.

Critical3
High20
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-596509.1criticalbc-javaIn Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value.34d ago
CVE-2026-580629.1criticalbc-javaIn Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate.34d ago
CVE-2026-87639.1criticalbc-javaIn Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI.34d ago
CVE-2026-128178.6highbc-javaIn Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data.34d ago
CVE-2026-121858.6highbc-javaIn Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check.34d ago
CVE-2026-150558.2highbc-javaIn Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input.34d ago
CVE-2026-596517.5highbc-javaIn Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key.34d ago
CVE-2026-580597.5highbc-javaIn Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names.34d ago
CVE-2026-580607.5highbc-javaIn Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify.34d ago
CVE-2026-580617.5highbc-javaIn Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check.34d ago
CVE-2026-128027.5highbc-javaIn Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption.34d ago
CVE-2026-128037.5highbc-javaIn Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEA34d ago
CVE-2026-128167.5highbc-javaIn Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split.34d ago
CVE-2026-128527.5highbc-javaIn Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds ch34d ago
CVE-2026-135067.5highbc-javaIn Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard.34d ago
CVE-2026-135867.5highbc-javaIn Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS).34d ago
CVE-2026-596447.5highbc-javaIn Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.34d ago
CVE-2026-146827.5highbc-javaIn Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read.34d ago
CVE-2026-596427.5highbc-javaIn Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present.34d ago
CVE-2026-596397.5highbc-javaIn Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers.34d ago
CVE-2026-596457.5highbc-javaIn Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 sch34d ago
CVE-2026-596467.5highbc-javaIn Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length.34d ago
CVE-2026-596497.5highbc-javaIn Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory.34d ago

Filter the full tracker by Bouncycastle