Legion of the Bouncy Castle Inc BC-JAVA是Legion of the Bouncy Castle Inc组织的一个提供加密算法的Java组件。 Legion of the Bouncy Castle Inc BC-JAVA 1.85之前版本、Bouncy Castle for Java LTS 2.73.12之前版本以及Bouncy Castle for Java FIPS 1.0.12之前版本、2.0.12之前版本和2.1.12之前版本存在资源管理错误漏洞,该漏洞源
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.0< 1.0.12 |
affected |
2.0.0< 2.0.12 |
affected | ||
2.1.0< 2.1.12 |
affected | ||
| Legion of the Bouncy Castle Inc. | BC-JAVA | < 1.85 |
affected |
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0< 2.73.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 0 ~ 1.85 | - |
|
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 ~ 2.73.12 | - |
|
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.0 ~ 1.0.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59638 | 9.3 CRITICAL | JSSE hostname verifier CN-fallback enabled by default despite documented opt-in |
| CVE-2026-58062 | 9.3 CRITICAL | Stapled OCSP response accepted without binding to the checked certificate |
| CVE-2026-8763 | 9.3 CRITICAL | Name Constraints bypass via trailing dot in rfc822Name and URI |
| CVE-2026-59650 | 9.3 CRITICAL | MTI/A0 DH agreement exponentiates unvalidated peer value |
| CVE-2026-12860 | 8.7 HIGH | RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path |
| CVE-2026-12852 | 8.7 HIGH | MLS wire decoder allocates attacker-declared opaque length before bounds check |
| CVE-2026-14682 | 8.7 HIGH | Possible OOM from unbounded up-front allocation on a definite-length read |
| CVE-2026-12803 | 8.7 HIGH | KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) |
| CVE-2026-58061 | 8.7 HIGH | CCM-family modes write plaintext to caller buffer before tag check |
| CVE-2026-58059 | 8.7 HIGH | Quadratic-time escaping when stringifying X.500 distinguished names |
| CVE-2026-58060 | 8.7 HIGH | HSS public-key level count unbounded, enabling huge allocation on verify |
| CVE-2026-59644 | 8.7 HIGH | MLS hash-ratchet honours arbitrary 32-bit generation counter from sender |
| CVE-2026-59645 | 8.7 HIGH | OER parser recurses without depth limit on self-referential IEEE 1609.2 schema |
| CVE-2026-59642 | 8.7 HIGH | CMS AuthenticatedData content not bound to MAC when authAttrs present |
| CVE-2026-59641 | 8.7 HIGH | S/MIME validator trusts signer-asserted signingTime for path validation |
| CVE-2026-12816 | 8.7 HIGH | IESEngine stream-mode MAC forgery via length-dependent KDF split |
| CVE-2026-12817 | 8.7 HIGH | OpenPGP AEAD decryption skips final tag on chunk-aligned data |
| CVE-2026-59643 | 8.7 HIGH | OpenPGP inline-signature policy failures silently ignored |
| CVE-2026-59646 | 8.7 HIGH | DTLS handshake reassembler allocates buffer from unchecked 24-bit length |
| CVE-2026-59640 | 8.7 HIGH | OpenPGP CFB quick-check oracle active on symmetric/session-key paths |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet