Bouncycastle
Bouncycastle Bouncy Castle: vulnerabilidades y CVE
Bouncycastle Bouncy Castle tiene 11 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses10
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85515 | Alta (8.2) | 0.16% | — | 3 oct 2026 | In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 sec. 13.7 permits an… |
| CVE-2026-71892 | Media (6.9) | 0.17% | — | 3 oct 2026 | In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709… |
| CVE-2026-71891 | Alta (7.1) | 0.17% | — | 3 oct 2026 | In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it,… |
| CVE-2026-71890 | Alta (8.7) | 0.25% | — | 3 oct 2026 | In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by type and bounded the… |
| CVE-2026-71888 | Alta (8.7) | 0.11% | — | 3 oct 2026 | In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652… |
| CVE-2026-71887 | Alta (8.2) | 0.09% | — | 3 oct 2026 | In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification)… |
| CVE-2026-71886 | Alta (8.2) | 0.17% | — | 3 oct 2026 | In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component… |
| CVE-2026-71885 | Crítica (9.2) | 0.19% | — | 3 oct 2026 | In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the… |
| CVE-2026-18036 | Alta (8.2) | 0.28% | — | 2 oct 2026 | In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer… |
| CVE-2026-17507 | Alta (8.7) | 0.32% | — | 2 oct 2026 | In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with the top bit set decodes to a negative number. That is a… |
| CVE-2024-30172 | Alta (7.5) | 0.75% | — | 14 may 2024 | An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.