Vulnerabilities in Legion of the Bouncy Castle Inc.
48 resultsVexday analysis
A Legion of the Bouncy Castle Inc. apresenta 13 vulnerabilidades catalogadas, com apenas 1 crítica e nenhuma sob ataque ativo no momento. A fraqueza dominante (CWE-400: Uncontrolled Resource Consumption) sugere problemas de negação de serviço, e o ritmo recente de 2 publicações em 90 dias indica atividade contínua de descoberta, mas sem pressão imediata de exploração em campo.
CVE-2026-59640HIGHOpenPGP CFB quick-check oracle active on symmetric/session-key pathsEPSS 0.3%CVE-2026-59638CRITICALJSSE hostname verifier CN-fallback enabled by default despite documented opt-inEPSS 0.3%CVE-2024-14041HIGHML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash)EPSS 0.3%CVE-2026-15055MEDIUMPKCS#8 / PBES2 decryptors honour unbounded KDF cost from inputEPSS 0.3%CVE-2026-14682HIGHPossible OOM from unbounded up-front allocation on a definite-length readEPSS 0.3%CVE-2025-14813CRITICALGOSTCTR implementation unable to process more than 255 blocks correctlyEPSS 0.3%CVE-2026-12852HIGHMLS wire decoder allocates attacker-declared opaque length before bounds checkEPSS 0.3%CVE-2026-59652MEDIUMLDAP filter injection in legacy jdk1.4 LDAPStoreHelperEPSS 0.3%CVE-2026-12185HIGHBKS/UBER keystore allocates from untrusted lengths before integrity checkEPSS 0.3%CVE-2026-58062CRITICALStapled OCSP response accepted without binding to the checked certificateEPSS 0.3%CVE-2026-13505HIGHZeroisation of sensitive key material on garbage collection relies on finalizationEPSS 0.3%CVE-2026-59651HIGHBKS keystore accepts legacy version with 16-bit integrity MAC keyEPSS 0.2%CVE-2026-59639HIGHCMS verifySignatures returns true for SignedData with zero signersEPSS 0.2%CVE-2026-59643HIGHOpenPGP inline-signature policy failures silently ignoredEPSS 0.2%CVE-2026-58061HIGHCCM-family modes write plaintext to caller buffer before tag checkEPSS 0.2%CVE-2026-59641HIGHS/MIME validator trusts signer-asserted signingTime for path validationEPSS 0.2%CVE-2026-12803HIGHKCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)EPSS 0.2%CVE-2026-59642HIGHCMS AuthenticatedData content not bound to MAC when authAttrs presentEPSS 0.2%CVE-2026-12816HIGHIESEngine stream-mode MAC forgery via length-dependent KDF splitEPSS 0.2%CVE-2026-12817HIGHOpenPGP AEAD decryption skips final tag on chunk-aligned dataEPSS 0.2%