Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.34% | — | Bouncycastle Bc-javaBouncycastle Bctls-fipsBouncycastle Bouncy Castle FOR Java LTS | 3/8/2026 | 28/8/2026 | In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series). | |
| Analizada | Media (5.3) | 0.34% | — | Bouncycastle Bc-javaBouncycastle Bcpkix-fipsBouncycastle Bouncy Castle FOR Java LTS | 3/8/2026 | 28/8/2026 | In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). | |
| En análisis | Alta (7.1) | 0.29% | — | Bouncycastle Bc-javaBouncycastle Bouncy Castle FOR Java LTS | 3/8/2026 | 28/8/2026 | In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12. | |
| Aplazada | Media (5.9) | 0.16% | — | Legion OF THE Bouncy Castle INC Bouncy Castle FOR Java FipsAIBouncycastle Bouncy Castle FOR Java LTSAI | 24/10/2025 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files… | |
| Aplazada | Ninguna (0) | 0.18% | — | Bouncycastle Bouncy Castle FOR JavaAI | 22/8/2025 | 17/6/2026 | Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0. | |
| Aplazada | Media (5.9) | 0.16% | — | Legion OF THE Bouncy Castle INC Bouncy Castle FOR Java FipsAIBouncycastle Bouncy Castle FOR Java LTSAI | 22/8/2025 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files… | |
| Aplazada | Baja (1) | 0.15% | — | Bouncycastle Bouncy Castle FOR JavaAI | 16/8/2025 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader. This issue affects Bouncy Castle for Java - BC-FJA… | |
| Modificada | Media (5.5) | 1.0% | — | Bouncycastle Bouncy Castle FOR JavaBouncycastle Fips Java API | 23/11/2023 | 17/6/2026 | Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through… |