Skip to content

robolectric-4.14.1.jar: 22 vulnerabilities (highest severity is: 10.0) #688

Description

@mend-bolt-for-github
Vulnerable Library - robolectric-4.14.1.jar

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (robolectric version) Remediation Possible**
CVE-2026-5598 Critical 10.0 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-8763 Critical 9.1 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-59650 Critical 9.1 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-58062 Critical 9.1 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2025-14813 Critical 9.0 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-58061 High 7.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-58060 High 7.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-58059 High 7.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-14682 High 7.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-13506 High 7.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-12860 High 7.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-12816 High 7.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-12803 High 7.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-59652 Medium 6.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-59651 Medium 6.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-12185 Medium 6.5 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-59648 Medium 5.3 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-59647 Medium 5.3 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-0636 Medium 5.3 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-58063 Medium 4.3 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-15055 Medium 4.3 bcprov-jdk18on-1.78.1.jar Transitive N/A*
CVE-2026-13586 Medium 4.3 bcprov-jdk18on-1.78.1.jar Transitive N/A*

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2026-5598

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules).
This vulnerability is associated with program files FrodoEngine.Java.
This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

Publish Date: 2026-04-15

URL: CVE-2026-5598

CVSS 3 Score Details (10.0)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-15

Fix Resolution: https://github.com/bcgit/bc-java.git - r1rv84,org.bouncycastle:bcprov-jdk18on:1.84,org.bouncycastle:bcprov-jdk14:1.84,org.bouncycastle:bcprov-jdk15to18:1.84

Step up your Open Source Security Game with Mend here

CVE-2026-8763

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-8763

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bc-fips:2.1.3,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-59650

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Publish Date: 2026-08-03

URL: CVE-2026-59650

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-58062

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-58062

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2025-14813

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).
This vulnerability is associated with program files G3413CTRBlockCipher.
This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

Publish Date: 2026-04-15

URL: CVE-2025-14813

CVSS 3 Score Details (9.0)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-15

Fix Resolution: https://github.com/bcgit/bc-java.git - r1rv84,org.bouncycastle:bcprov-jdk18on:1.84,org.bouncycastle:bcprov-jdk14:1.84,org.bouncycastle:bcprov-jdk15to18:1.84

Step up your Open Source Security Game with Mend here

CVE-2026-58061

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-58061

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:1.0.2.7,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-58060

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-58060

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:2.0.2,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-58059

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-58059

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-14682

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.

Publish Date: 2026-08-03

URL: CVE-2026-14682

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-13506

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-13506

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-12860

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, RSA PKCS#⁠1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Publish Date: 2026-08-03

URL: CVE-2026-12860

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-12816

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Publish Date: 2026-08-03

URL: CVE-2026-12816

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-12803

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Publish Date: 2026-08-03

URL: CVE-2026-12803

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-59652

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.

Publish Date: 2026-08-03

URL: CVE-2026-59652

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-59651

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Publish Date: 2026-08-03

URL: CVE-2026-59651

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-12185

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Publish Date: 2026-08-03

URL: CVE-2026-12185

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-59648

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-59648

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcpg-fips:1.0.13,org.bouncycastle:bcpg-jdk15to18:1.85,org.bouncycastle:bcpg-fips:2.0.13,org.bouncycastle:bcpg-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcpg-lts8on:2.73.12,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpg-fips:2.1.13,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-59647

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-59647

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-fips:2.1.12,org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcpkix-fips:2.0.12,org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-0636

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).
This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

Publish Date: 2026-04-15

URL: CVE-2026-0636

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-15

Fix Resolution: https://github.com/bcgit/bc-java.git - r1rv84,org.bouncycastle:bcprov-jdk18on:1.84

Step up your Open Source Security Game with Mend here

CVE-2026-58063

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-58063

CVSS 3 Score Details (4.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:2.1.3,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-15055

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, PKCS#⁠8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-15055

CVSS 3 Score Details (4.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcpkix-fips:2.1.12,org.bouncycastle:bcpkix-fips:2.0.12,org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

CVE-2026-13586

Vulnerable Library - bcprov-jdk18on-1.78.1.jar

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.

Library home page: https://www.bouncycastle.org/java.html

Dependency Hierarchy:

  • robolectric-4.14.1.jar (Root Library)
    • bcprov-jdk18on-1.78.1.jar (Vulnerable Library)

Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1

Found in base branch: develop

Vulnerability Details

In Bouncy Castle for Java before 1.85, PKCS#⁠12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Publish Date: 2026-08-03

URL: CVE-2026-13586

CVSS 3 Score Details (4.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85

Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions