Search CVE reports


Toggle filters

1 – 10 of 33 results


CVE-2025-12194

Medium priority
Needs evaluation

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-8916

Medium priority
Needs evaluation

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-8885

Medium priority
Needs evaluation

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-30172

Medium priority
Needs evaluation

An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-30171

Medium priority
Needs evaluation

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-29857

Medium priority
Needs evaluation

An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-34447

Medium priority
Needs evaluation

An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-33202

Medium priority
Needs evaluation

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates,...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-33201

Medium priority
Needs evaluation

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-45146

Medium priority
Needs evaluation

An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages