Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Legion of the Bouncy Castle Inc. — Vulnerabilities & Security Advisories 48

Browse all 48 CVE security advisories affecting Legion of the Bouncy Castle Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Legion of the Bouncy Castle Inc. develops the Bouncy Castle cryptographic library, widely used for Java and C# cryptographic operations. Historically, vulnerabilities in their software have commonly included remote code execution, cross-site scripting, and privilege escalation flaws. The library's extensive integration into enterprise systems has made it a target for attackers. While no major public security incidents have been documented, the 11 CVEs on record highlight ongoing security challenges in maintaining cryptographic implementations. Regular updates and careful implementation remain critical for organizations using their libraries to prevent potential exploitation of these vulnerabilities.

CVE IDTitleCVSSSeverityPublished
CVE-2026-13505 Zeroisation of sensitive key material on garbage collection relies on finalization — BC-FJACWE-772 8.7 High2026-08-08
CVE-2026-8798 Native entropy source retries the CPU entropy instructions without limit — BC-FJACWE-835 8.7 High2026-08-08
CVE-2026-13586 PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) — BC-JAVACWE-770 5.3 Medium2026-08-03
CVE-2026-13506 Lazy ASN.1 sequence forcing resets nesting-depth guard — BC-JAVACWE-674 8.7 High2026-08-03
CVE-2026-12860 RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path — BC-JAVACWE-347 8.7 High2026-08-03
CVE-2026-12852 MLS wire decoder allocates attacker-declared opaque length before bounds check — BC-JAVACWE-789 8.7 High2026-08-03
CVE-2026-12817 OpenPGP AEAD decryption skips final tag on chunk-aligned data — BC-JAVACWE-354 8.7 High2026-08-03
CVE-2026-12816 IESEngine stream-mode MAC forgery via length-dependent KDF split — BC-JAVACWE-354 8.7 High2026-08-03
CVE-2026-12803 KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) — BC-JAVACWE-354 8.7 High2026-08-03
CVE-2026-12802 CMS AuthEnvelopedData fails to enforce tag-length on decryption — BC-JAVACWE-354 8.7 High2026-08-03
CVE-2026-14682 Possible OOM from unbounded up-front allocation on a definite-length read — BC-JAVACWE-789 8.7 High2026-08-03
CVE-2026-58059 Quadratic-time escaping when stringifying X.500 distinguished names — BC-JAVACWE-407 8.7 High2026-08-03
CVE-2026-58060 HSS public-key level count unbounded, enabling huge allocation on verify — BC-JAVACWE-789 8.7 High2026-08-03
CVE-2026-58061 CCM-family modes write plaintext to caller buffer before tag check — BC-JAVACWE-354 8.7 High2026-08-03
CVE-2026-58062 Stapled OCSP response accepted without binding to the checked certificate — BC-JAVACWE-295 9.3 Critical2026-08-03
CVE-2026-58063 BCFKS keystore load honours unbounded KDF cost from untrusted file — BC-JAVACWE-770 5.3 Medium2026-08-03
CVE-2026-59638 JSSE hostname verifier CN-fallback enabled by default despite documented opt-in — BC-JAVACWE-297 9.3 Critical2026-08-03
CVE-2026-59639 CMS verifySignatures returns true for SignedData with zero signers — BC-JAVACWE-347 8.7 High2026-08-03
CVE-2026-59640 OpenPGP CFB quick-check oracle active on symmetric/session-key paths — BC-JAVACWE-203 8.7 High2026-08-03
CVE-2026-59641 S/MIME validator trusts signer-asserted signingTime for path validation — BC-JAVACWE-345 8.7 High2026-08-03
CVE-2026-59642 CMS AuthenticatedData content not bound to MAC when authAttrs present — BC-JAVACWE-354 8.7 High2026-08-03
CVE-2026-59643 OpenPGP inline-signature policy failures silently ignored — BC-JAVACWE-347 8.7 High2026-08-03
CVE-2026-59644 MLS hash-ratchet honours arbitrary 32-bit generation counter from sender — BC-JAVACWE-834 8.7 High2026-08-03
CVE-2026-59645 OER parser recurses without depth limit on self-referential IEEE 1609.2 schema — BC-JAVACWE-674 8.7 High2026-08-03
CVE-2026-59646 DTLS handshake reassembler allocates buffer from unchecked 24-bit length — BC-JAVACWE-789 8.7 High2026-08-03
CVE-2026-59647 CRMF/CMP password-MAC honours unbounded iteration count — BC-JAVACWE-770 6.9 Medium2026-08-03
CVE-2026-59648 OpenPGP Argon2 S2K honours attacker-chosen memory and passes — BC-JAVACWE-770 6.9 Medium2026-08-03
CVE-2026-59649 OpenPGP user-attribute subpacket length bounded only by JVM max memory — BC-JAVACWE-789 8.7 High2026-08-03
CVE-2026-59650 MTI/A0 DH agreement exponentiates unvalidated peer value — BC-JAVACWE-20 9.3 Critical2026-08-03
CVE-2026-59651 BKS keystore accepts legacy version with 16-bit integrity MAC key — BC-JAVACWE-326 7.1 High2026-08-03

This page lists every published CVE security advisory associated with Legion of the Bouncy Castle Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.