Vulnerable Library - robolectric-4.14.1.jar
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Dependency |
Type |
Fixed in (robolectric version) |
Remediation Possible** |
| CVE-2026-5598 |
Critical |
10.0 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-8763 |
Critical |
9.1 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-59650 |
Critical |
9.1 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-58062 |
Critical |
9.1 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2025-14813 |
Critical |
9.0 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-58061 |
High |
7.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-58060 |
High |
7.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-58059 |
High |
7.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-14682 |
High |
7.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-13506 |
High |
7.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-12860 |
High |
7.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-12816 |
High |
7.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-12803 |
High |
7.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-59652 |
Medium |
6.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-59651 |
Medium |
6.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-12185 |
Medium |
6.5 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-59648 |
Medium |
5.3 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-59647 |
Medium |
5.3 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-0636 |
Medium |
5.3 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-58063 |
Medium |
4.3 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-15055 |
Medium |
4.3 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-13586 |
Medium |
4.3 |
bcprov-jdk18on-1.78.1.jar |
Transitive |
N/A* |
❌ |
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2026-5598
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules).
This vulnerability is associated with program files FrodoEngine.Java.
This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Publish Date: 2026-04-15
URL: CVE-2026-5598
CVSS 3 Score Details (10.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-15
Fix Resolution: https://github.com/bcgit/bc-java.git - r1rv84,org.bouncycastle:bcprov-jdk18on:1.84,org.bouncycastle:bcprov-jdk14:1.84,org.bouncycastle:bcprov-jdk15to18:1.84
Step up your Open Source Security Game with Mend here
CVE-2026-8763
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-8763
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bc-fips:2.1.3,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-59650
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-59650
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-58062
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-58062
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2025-14813
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).
This vulnerability is associated with program files G3413CTRBlockCipher.
This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Publish Date: 2026-04-15
URL: CVE-2025-14813
CVSS 3 Score Details (9.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-15
Fix Resolution: https://github.com/bcgit/bc-java.git - r1rv84,org.bouncycastle:bcprov-jdk18on:1.84,org.bouncycastle:bcprov-jdk14:1.84,org.bouncycastle:bcprov-jdk15to18:1.84
Step up your Open Source Security Game with Mend here
CVE-2026-58061
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-58061
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:1.0.2.7,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-58060
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-58060
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:2.0.2,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-58059
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-58059
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-14682
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
Publish Date: 2026-08-03
URL: CVE-2026-14682
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-13506
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-13506
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-12860
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-12860
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-12816
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-12816
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-12803
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-12803
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-59652
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
Publish Date: 2026-08-03
URL: CVE-2026-59652
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-59651
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-59651
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-12185
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-12185
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-59648
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-59648
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcpg-fips:1.0.13,org.bouncycastle:bcpg-jdk15to18:1.85,org.bouncycastle:bcpg-fips:2.0.13,org.bouncycastle:bcpg-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcpg-lts8on:2.73.12,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpg-fips:2.1.13,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-59647
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-59647
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-fips:2.1.12,org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcpkix-fips:2.0.12,org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-0636
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).
This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Publish Date: 2026-04-15
URL: CVE-2026-0636
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-15
Fix Resolution: https://github.com/bcgit/bc-java.git - r1rv84,org.bouncycastle:bcprov-jdk18on:1.84
Step up your Open Source Security Game with Mend here
CVE-2026-58063
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-58063
CVSS 3 Score Details (4.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:2.1.3,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-15055
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-15055
CVSS 3 Score Details (4.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcpkix-fips:2.1.12,org.bouncycastle:bcpkix-fips:2.0.12,org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
CVE-2026-13586
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
- robolectric-4.14.1.jar (Root Library)
- ❌ bcprov-jdk18on-1.78.1.jar (Vulnerable Library)
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-13586
CVSS 3 Score Details (4.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules).
This vulnerability is associated with program files FrodoEngine.Java.
This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Publish Date: 2026-04-15
URL: CVE-2026-5598
CVSS 3 Score Details (10.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-04-15
Fix Resolution: https://github.com/bcgit/bc-java.git - r1rv84,org.bouncycastle:bcprov-jdk18on:1.84,org.bouncycastle:bcprov-jdk14:1.84,org.bouncycastle:bcprov-jdk15to18:1.84
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-8763
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bc-fips:2.1.3,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-59650
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-58062
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).
This vulnerability is associated with program files G3413CTRBlockCipher.
This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Publish Date: 2026-04-15
URL: CVE-2025-14813
CVSS 3 Score Details (9.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-04-15
Fix Resolution: https://github.com/bcgit/bc-java.git - r1rv84,org.bouncycastle:bcprov-jdk18on:1.84,org.bouncycastle:bcprov-jdk14:1.84,org.bouncycastle:bcprov-jdk15to18:1.84
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-58061
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:1.0.2.7,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-58060
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:2.0.2,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-58059
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
Publish Date: 2026-08-03
URL: CVE-2026-14682
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-13506
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-12860
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-12816
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-12803
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
Publish Date: 2026-08-03
URL: CVE-2026-59652
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-59651
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Publish Date: 2026-08-03
URL: CVE-2026-12185
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-59648
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcpg-fips:1.0.13,org.bouncycastle:bcpg-jdk15to18:1.85,org.bouncycastle:bcpg-fips:2.0.13,org.bouncycastle:bcpg-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcpg-lts8on:2.73.12,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpg-fips:2.1.13,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-59647
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-fips:2.1.12,org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcpkix-fips:2.0.12,org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).
This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Publish Date: 2026-04-15
URL: CVE-2026-0636
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-04-15
Fix Resolution: https://github.com/bcgit/bc-java.git - r1rv84,org.bouncycastle:bcprov-jdk18on:1.84
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-58063
CVSS 3 Score Details (4.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:2.1.3,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-15055
CVSS 3 Score Details (4.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcpkix-fips:2.1.12,org.bouncycastle:bcpkix-fips:2.0.12,org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here
Vulnerable Library - bcprov-jdk18on-1.78.1.jar
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
Library home page: https://www.bouncycastle.org/java.html
Dependency Hierarchy:
Found in HEAD commit: 77a89ac5bd1696a91ab9e7654223c13959e4b2c1
Found in base branch: develop
Vulnerability Details
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Publish Date: 2026-08-03
URL: CVE-2026-13586
CVSS 3 Score Details (4.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-03
Fix Resolution: org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,https://github.com/bcgit/bc-java.git - r1rv85
Step up your Open Source Security Game with Mend here