Search CVE reports


Toggle filters

241 – 250 of 42038 results

Status is adjusted based on your filters.


CVE-2026-14682

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-13586

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-13506

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12860

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12852

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12817

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12816

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12803

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12802

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-58063

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages