bouncycastle
OSS Librariesoss-project
Latest CVEs
The 15 most recently published vulnerabilities affecting bouncycastle.
- CVE-2026-13586PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)7.5
- CVE-2026-13506Lazy ASN.1 sequence forcing resets nesting-depth guard7.5
- CVE-2026-12860RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path5.3
- CVE-2026-12852MLS wire decoder allocates attacker-declared opaque length before bounds check7.5
- CVE-2026-12817OpenPGP AEAD decryption skips final tag on chunk-aligned data8.6
- CVE-2026-12816IESEngine stream-mode MAC forgery via length-dependent KDF split7.5
- CVE-2026-12803KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)7.5
- CVE-2026-12802CMS AuthEnvelopedData fails to enforce tag-length on decryption7.5
- CVE-2026-14682Possible OOM from unbounded up-front allocation on a definite-length read7.5
- CVE-2026-58059Quadratic-time escaping when stringifying X.500 distinguished names7.5
- CVE-2026-58060HSS public-key level count unbounded, enabling huge allocation on verify7.5
- CVE-2026-58061CCM-family modes write plaintext to caller buffer before tag check7.5
- CVE-2026-58062Stapled OCSP response accepted without binding to the checked certificate9.1
- CVE-2026-58063BCFKS keystore load honours unbounded KDF cost from untrusted file5.3
- CVE-2026-59638JSSE hostname verifier CN-fallback enabled by default despite documented opt-in6.5