Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Legion of the Bouncy Castle Inc. — Vulnerabilities & Security Advisories 84

Browse all 84 CVE security advisories affecting Legion of the Bouncy Castle Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Legion of the Bouncy Castle Inc. develops the Bouncy Castle cryptographic library, widely used for Java and C# cryptographic operations. Historically, vulnerabilities in their software have commonly included remote code execution, cross-site scripting, and privilege escalation flaws. The library's extensive integration into enterprise systems has made it a target for attackers. While no major public security incidents have been documented, the 11 CVEs on record highlight ongoing security challenges in maintaining cryptographic implementations. Regular updates and careful implementation remain critical for organizations using their libraries to prevent potential exploitation of these vulnerabilities.

Found 21 results / 84 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-103604 Quadratic-time escaping when converting X.509 distinguished names to strings — bc-csharp CWE-407 8.7 High 2026-10-02
CVE-2026-103603 Unbounded HSS public key level count allows huge array allocation during signature verification — bc-csharp CWE-789 8.7 High 2026-10-02
CVE-2026-103602 Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts — bc-csharp CWE-295 8.2 High 2026-10-02
CVE-2026-103601 CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer after a failed tag check — bc-csharp CWE-354 8.2 High 2026-10-02
CVE-2026-103600 Unbounded ASN.1 nesting depth causes process-terminating stack overflow — bc-csharp CWE-674 8.7 High 2026-10-02
CVE-2026-63578 Unbounded PBE iteration count when decrypting PKCS#8 private keys — bc-csharp CWE-770 7.1 High 2026-10-02
CVE-2026-63577 Name Constraints bypass: directoryName constraint matched at any position in the DN instead of as a prefix — bc-csharp CWE-295 8.2 High 2026-10-02
CVE-2026-63576 URI name constraints checked against a mis-parsed host — bc-csharp CWE-295 8.2 High 2026-10-02
CVE-2026-63575 PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count — bc-csharp CWE-835 7.1 High 2026-10-02
CVE-2026-63574 Unbounded allocation from OpenPGP signature and user attribute subpacket lengths — bc-csharp CWE-789 8.7 High 2026-10-02
CVE-2026-63573 Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap — bc-csharp CWE-203 8.2 High 2026-10-02
CVE-2026-63572 Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files — bc-csharp CWE-770 7.1 High 2026-10-02
CVE-2026-63571 Attribute certificate path validation does not verify the attribute certificate's signature — bc-csharp CWE-347 8.7 High 2026-10-02
CVE-2026-63570 Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links — bc-csharp CWE-835 7.1 High 2026-10-02
CVE-2026-63569 MTI/A0 DHAgreement does not validate the peer's ephemeral value — bc-csharp CWE-20 9.1 Critical 2026-10-02
CVE-2026-63568 Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion — bc-csharp CWE-770 8.7 High 2026-10-02
CVE-2026-63567 IesEngine block-cipher mode checks padding before MAC (CBC padding oracle) — bc-csharp CWE-203 8.2 High 2026-10-02
CVE-2026-63566 DTLS handshake reassembler allocates buffer from unchecked 24-bit length — bc-csharp CWE-789 8.7 High 2026-10-02
CVE-2026-16001 IesEngine stream-mode MAC forgery via length-dependent KDF split — bc-csharp CWE-354 8.2 High 2026-10-02
CVE-2026-16000 KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is used — bc-csharp CWE-325 8.7 High 2026-10-02
CVE-2026-15999 AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication — bc-csharp CWE-354 8.2 High 2026-10-02

This page lists every published CVE security advisory associated with Legion of the Bouncy Castle Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.