Search CVE reports


Toggle filters

151 – 160 of 44355 results

Status is adjusted based on your filters.


CVE-2026-12817

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12816

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12803

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12802

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-58063

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-58062

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-58061

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-58060

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-58059

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-8763

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages