在 Bouncy Castle for Java 1.86 之前的版本中,原生 JCA 提供程序对传统 PBES1(PKCS#5 方案 1)和 PKCS#12 PBE 密码族在基于密码的密钥派生过程中,所使用的迭代次数直接从不可信输入中获取,且未进行上限限制。因此,攻击者可以通过提供极小的输入值,迫使系统在验证任何内容之前执行任意数量的计算工作,从而导致拒绝服务(DoS)攻击。 PKCS12PBE 及其对象标识符别名以及 PBKDF1 的 AlgorithmParameters 实现允许接受来自编码后的 PKCS1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 0 ~ 1.86 | - |
|
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 ~ 2.73.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71885 | 9.2 CRITICAL | MLS X.509 credential not bound to the LeafNode signature key |
| CVE-2026-71888 | 8.7 HIGH | CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent |
| CVE-2026-71889 | 8.7 HIGH | PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate |
| CVE-2026-71890 | 8.7 HIGH | MLS external commit can remove an arbitrary group member |
| CVE-2026-85515 | 8.2 HIGH | OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check |
| CVE-2026-71887 | 8.2 HIGH | OpenPGP data signature accepted from a signing subkey without cross-certification |
| CVE-2026-71883 | 8.2 HIGH | Native AES packet cipher returns the raw AES key on an alias |
| CVE-2026-71886 | 8.2 HIGH | OpenPGP certification accepted from a subkey without certification authority |
| CVE-2026-71891 | 7.1 HIGH | BLS12-381 key validation accepts a public key built on a foreign curve |
| CVE-2026-71892 | 6.9 MEDIUM | CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys |
| CVE-2026-18040 | 5.9 MEDIUM | HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-depen |
No comments yet