Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Legion of the Bouncy Castle Inc. — Vulnerabilities & Security Advisories 84

Browse all 84 CVE security advisories affecting Legion of the Bouncy Castle Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Legion of the Bouncy Castle Inc. develops the Bouncy Castle cryptographic library, widely used for Java and C# cryptographic operations. Historically, vulnerabilities in their software have commonly included remote code execution, cross-site scripting, and privilege escalation flaws. The library's extensive integration into enterprise systems has made it a target for attackers. While no major public security incidents have been documented, the 11 CVEs on record highlight ongoing security challenges in maintaining cryptographic implementations. Regular updates and careful implementation remain critical for organizations using their libraries to prevent potential exploitation of these vulnerabilities.

CVE ID Title CVSS Severity Published
CVE-2026-59646 DTLS handshake reassembler allocates buffer from unchecked 24-bit length — BC-JAVA CWE-789 8.7 High 2026-08-03
CVE-2026-59647 CRMF/CMP password-MAC honours unbounded iteration count — BC-JAVA CWE-770 6.9 Medium 2026-08-03
CVE-2026-59648 OpenPGP Argon2 S2K honours attacker-chosen memory and passes — BC-JAVA CWE-770 6.9 Medium 2026-08-03
CVE-2026-59649 OpenPGP user-attribute subpacket length bounded only by JVM max memory — BC-JAVA CWE-789 8.7 High 2026-08-03
CVE-2026-59650 MTI/A0 DH agreement exponentiates unvalidated peer value — BC-JAVA CWE-20 9.3 Critical 2026-08-03
CVE-2026-59651 BKS keystore accepts legacy version with 16-bit integrity MAC key — BC-JAVA CWE-326 7.1 High 2026-08-03
CVE-2026-59652 LDAP filter injection in legacy jdk1.4 LDAPStoreHelper — BC-JAVA CWE-90 6.9 Medium 2026-08-03
CVE-2026-12185 BKS/UBER keystore allocates from untrusted lengths before integrity check — BC-JAVA CWE-789 7.1 High 2026-08-03
CVE-2026-8763 Name Constraints bypass via trailing dot in rfc822Name and URI — BC-JAVA CWE-295 9.3 Critical 2026-08-03
CVE-2026-15055 PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input — BC-JAVA CWE-770 5.3 Medium 2026-08-03
CVE-2024-14041 ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash) — BC-JAVA CWE-208 8.2 High 2026-07-28
CVE-2026-15997 Native ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow in a crafted encoded state — BC-LTS CWE-787 - - 2026-07-16
CVE-2026-8149 GCM chunking can lead to bad tag exception on decryption — BC-LTS CWE-1068 9.1AI Critical AI 2026-05-08
CVE-2026-3505 Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion. — BC-JAVA CWE-770 8.7 High 2026-04-15
CVE-2026-5588 PKIX draft CompositeVerifier accepts empty signature sequence as valid. — BC-JAVA CWE-327 6.3 Medium 2026-04-15
CVE-2026-5598 Non-constant time comparisons risk private key leakage in FrodoKEM. — BC-JAVA CWE-385 8.9 High 2026-04-15
CVE-2026-0636 LDAP Injection Vulnerability in LDAPStoreHelper.java — BC-JAVA CWE-90 5.5 Medium 2026-04-15
CVE-2025-14813 GOSTCTR implementation unable to process more than 255 blocks correctly — BC-JAVA CWE-327 9.3 Critical 2026-04-15
CVE-2025-12194 Bouncy Castle Java 安全漏洞 — Bouncy Castle for Java FIPS CWE-400 7.5 - 2025-10-24
CVE-2025-9340 native encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output. — Bouncy Castle for Java CWE-787 9.8AI Critical AI 2025-08-22
CVE-2025-9341 Garbage collection can delay for AES CBC Native support, resulting in heap exhaustion — Bouncy Castle for Java FIPS CWE-400 7.5AI High AI 2025-08-22
CVE-2025-9092 Hybrid Module Deployment in Multi-JVM Environments Leading to Resource Exhaustion — Bouncy Castle for Java - BC-FJA 2.1.0 CWE-400 7.5AI High AI 2025-08-16
CVE-2025-8916 Possible DOS in processing large name constraint structures in PKIXCertPathReveiwer — BC Java CWE-770 7.5 - 2025-08-13
CVE-2025-8885 Possible DOS in processing specially formed ASN.1 Object Identifiers — BC Java CWE-770 7.5 - 2025-08-12

This page lists every published CVE security advisory associated with Legion of the Bouncy Castle Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.