« Volver al listado

Bouncycastle

Bouncycastle Bouncy Castle: vulnerabilidades y CVE

Bouncycastle Bouncy Castle tiene 11 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses10
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-85515Alta (8.2)0.16%—3 oct 2026
In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 sec. 13.7 permits an…
CVE-2026-71892Media (6.9)0.17%—3 oct 2026
In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709…
CVE-2026-71891Alta (7.1)0.17%—3 oct 2026
In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it,…
CVE-2026-71890Alta (8.7)0.25%—3 oct 2026
In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by type and bounded the…
CVE-2026-71888Alta (8.7)0.11%—3 oct 2026
In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652…
CVE-2026-71887Alta (8.2)0.09%—3 oct 2026
In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification)…
CVE-2026-71886Alta (8.2)0.17%—3 oct 2026
In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component…
CVE-2026-71885Crítica (9.2)0.19%—3 oct 2026
In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the…
CVE-2026-18036Alta (8.2)0.28%—2 oct 2026
In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer…
CVE-2026-17507Alta (8.7)0.32%—2 oct 2026
In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with the top bit set decodes to a negative number. That is a…
CVE-2024-30172Alta (7.5)0.75%—14 may 2024
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application9
  2. T1078 Valid Accounts3
  3. T1553.006 Code Signing Policy Modification2
  4. T1565.001 Stored Data Manipulation2
  5. T1203 Exploitation for Client Execution1
  6. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Bouncycastle