24h | 7d | 30d

Overview

  • Legion of the Bouncy Castle Inc.
  • BC-JAVA
  • bcpkix

03 Aug 2026
Published
03 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.17%

KEV

Description

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

Statistics

  • 1 Post
  • 14 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

  • 8
  • 6
  • 0
  • 19h ago

Overview

  • Legion of the Bouncy Castle Inc.
  • BC-JAVA
  • bcprov

03 Aug 2026
Published
03 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.33%

KEV

Description

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Statistics

  • 1 Post
  • 14 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

  • 8
  • 6
  • 0
  • 19h ago

Overview

  • Legion of the Bouncy Castle Inc.
  • BC-JAVA
  • bcprov

03 Aug 2026
Published
03 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.20%

KEV

Description

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Statistics

  • 1 Post
  • 14 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

  • 8
  • 6
  • 0
  • 19h ago

Overview

  • Legion of the Bouncy Castle Inc.
  • BC-JAVA
  • bcprov

03 Aug 2026
Published
03 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.21%

KEV

Description

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Statistics

  • 1 Post
  • 14 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

  • 8
  • 6
  • 0
  • 19h ago
Showing 61 to 64 of 64 CVEs