Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

59 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.2)0.16%—Bouncycastle Bouncy CastleAI3/10/20266/10/2026
In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 sec. 13.7 permits an implementation to release the cleartext of the fully authenticated chunks when streaming but requires…
Pendiente de análisisMedia (6.9)0.17%—Bouncycastle Bouncy CastleAI3/10/20266/10/2026
In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709 content-encryption key derivation (id-alg-cek-hkdf-sha256). The branch that should have selected the…
Pendiente de análisisAlta (7.1)0.17%—Bouncycastle Bouncy CastleAI3/10/20266/10/2026
In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it, accepted a public key built on a foreign ECCurve that merely shares BLS12-381's field characteristic. The…
Pendiente de análisisAlta (8.7)0.25%—Bouncycastle Bouncy CastleAI3/10/20266/10/2026
In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by type and bounded the removed leaf index but never established that the removed leaf had anything to do with the joiner.…
Pendiente de análisisAlta (8.7)0.11%—Bouncycastle Bouncy CastleAI3/10/20266/10/2026
In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652 sec. 9.1 pairs the two, requiring that authAttrs be present whenever digestAlgorithm is, and sec. 9.2…
Pendiente de análisisAlta (8.2)0.09%—Bouncycastle Bouncy CastleAI3/10/20266/10/2026
In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the case where that binding omits a Key Flags subpacket. RFC 9580 sec. 5.2.1.8 and sec. 10.1.3…
Pendiente de análisisAlta (8.2)0.17%—Bouncycastle Bouncy CastleAI3/10/20266/10/2026
In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component to have been granted the authority to certify. OpenPGPCertificate.getCertificationBy() and…
Pendiente de análisisCrítica (9.2)0.19%—Bouncycastle Bouncy CastleAI3/10/20266/10/2026
In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored…
En análisisAlta (7.1)0.21%—Legion OF THE Bouncy Castle INC BC CsharpAI2/10/20262/10/2026
Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an application that loads it and requests a key entry's certificate chain to cause a denial of service, in which the call never…
En análisisAlta (8.2)0.28%—Bouncycastle Bouncy CastleAI2/10/20262/10/2026
In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose latency depends on the secret operand. Polynomial.modQ divided by a variable divisor,…
En análisisAlta (8.7)0.32%—Bouncycastle Bouncy CastleAI2/10/20262/10/2026
In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with the top bit set decodes to a negative number. That is a legitimate encoding rather than malformed input, and it must still decode, since the MLS interop test…
En análisisAlta (8.2)0.47%—Legion OF THE Bouncy Castle INC BC CsharpAI2/10/20262/10/2026
Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack,…
En análisisAlta (8.2)0.17%—Legion OF THE Bouncy Castle BC CsharpAI2/10/20262/10/2026
Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed without a block cipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has observed one encrypted message with known plaintext to forge shorter…
AnalizadaAlta (8.7)0.33%—Bouncycastle Bc-javaBouncycastle Bctls-fipsBouncycastle Bouncy Castle FOR Java LTSBouncycastle Fips Java API3/8/202628/8/2026
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before…
AnalizadaMedia (5.3)0.35%—Bouncycastle Bc-javaBouncycastle Bouncy Castle FOR Java LTSBouncycastle Fips Java API3/8/202628/8/2026
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
AnalizadaAlta (8.7)0.44%—Bouncycastle Bc-javaBouncycastle Bouncy Castle FOR Java LTSBouncycastle Fips Java API3/8/202628/8/2026
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
AnalizadaAlta (8.7)0.17%—Bouncycastle Bc-javaBouncycastle Bouncy Castle FOR Java LTS3/8/202628/8/2026
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
AnalizadaAlta (8.7)0.17%—Bouncycastle Bc-javaBouncycastle Bcpg-fipsBouncycastle Bouncy Castle FOR Java LTS3/8/202631/8/2026
In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
AnalizadaAlta (8.7)0.18%—Bouncycastle Bc-javaBouncycastle Bouncy Castle FOR Java LTS3/8/20262/9/2026
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
AnalizadaAlta (8.7)0.20%—Bouncycastle Bc-javaBouncycastle Bouncy Castle FOR Java LTS3/8/20262/9/2026
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
AnalizadaAlta (8.7)0.15%—Bouncycastle Bc-javaBouncycastle Bcpkix-fipsBouncycastle Bouncy Castle FOR Java LTS3/8/20262/9/2026
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
AnalizadaMedia (5.3)0.42%—Bouncycastle Bc-javaBouncycastle Bouncy Castle FOR Java LTSBouncycastle Fips Java API3/8/20262/9/2026
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
AnalizadaCrítica (9.3)0.27%—Bouncycastle Bc-javaBouncycastle Bouncy Castle FOR Java LTSBouncycastle Fips Java API3/8/20262/9/2026
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
AnalizadaAlta (8.7)0.24%—Bouncycastle Bc-javaBouncycastle Bouncy Castle FOR Java LTSBouncycastle Fips Java API3/8/20262/9/2026
In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
AnalizadaAlta (8.7)0.62%—Bouncycastle Bc-javaBouncycastle Bouncy Castle FOR Java LTSBouncycastle Fips Java API3/8/20262/9/2026
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).