Search CVE reports


Toggle filters

1 – 10 of 88 results


CVE-2026-97873

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation with an iteration count taken from untrusted input without bounding it,...

1 affected package

bouncycastle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-85515

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 sec. 13.7 permits an...

1 affected package

bouncycastle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71892

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709...

1 affected package

bouncycastle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71891

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it, accepted a public...

1 affected package

bouncycastle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71890

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by type and bounded the removed...

1 affected package

bouncycastle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71889

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.509 name constraints to the...

1 affected package

bouncycastle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71888

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652 sec. 9.1 pairs...

1 affected package

bouncycastle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71887

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the...

1 affected package

bouncycastle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71886

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component to have...

1 affected package

bouncycastle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71885

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against...

1 affected package

bouncycastle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages