Vulnerabilidades en Legion of the Bouncy Castle Inc.
48 resultadosAnálisis Vexday
A Legion of the Bouncy Castle Inc. apresenta 13 vulnerabilidades catalogadas, com apenas 1 crítica e nenhuma sob ataque ativo no momento. A fraqueza dominante (CWE-400: Uncontrolled Resource Consumption) sugere problemas de negação de serviço, e o ritmo recente de 2 publicações em 90 dias indica atividade contínua de descoberta, mas sem pressão imediata de exploração em campo.
CVE-2026-3505HIGHUnbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.EPSS 0.8%CVE-2026-5598HIGHNon-constant time comparisons risk private key leakage in FrodoKEM.EPSS 0.7%CVE-2026-5588MEDIUMPKIX draft CompositeVerifier accepts empty signature sequence as valid.EPSS 0.6%CVE-2025-8885MEDIUMPossible DOS in processing specially formed ASN.1 Object IdentifiersEPSS 0.5%CVE-2026-0636MEDIUMLDAP Injection Vulnerability in LDAPStoreHelper.javaEPSS 0.5%CVE-2025-8916MEDIUMPossible DOS in processing large name constraint structures in PKIXCertPathReveiwerEPSS 0.5%CVE-2026-58060HIGHHSS public-key level count unbounded, enabling huge allocation on verifyEPSS 0.4%CVE-2026-59652MEDIUMLDAP filter injection in legacy jdk1.4 LDAPStoreHelperEPSS 0.3%CVE-2026-8763CRITICALName Constraints bypass via trailing dot in rfc822Name and URIEPSS 0.3%CVE-2026-58063MEDIUMBCFKS keystore load honours unbounded KDF cost from untrusted fileEPSS 0.3%CVE-2026-58059HIGHQuadratic-time escaping when stringifying X.500 distinguished namesEPSS 0.3%CVE-2026-8798HIGHNative entropy source retries the CPU entropy instructions without limitEPSS 0.3%CVE-2025-14813CRITICALGOSTCTR implementation unable to process more than 255 blocks correctlyEPSS 0.3%CVE-2026-13586MEDIUMPKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)EPSS 0.3%CVE-2026-59646HIGHDTLS handshake reassembler allocates buffer from unchecked 24-bit lengthEPSS 0.3%CVE-2026-59638CRITICALJSSE hostname verifier CN-fallback enabled by default despite documented opt-inEPSS 0.3%CVE-2024-14041HIGHML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash)EPSS 0.3%CVE-2026-12185HIGHBKS/UBER keystore allocates from untrusted lengths before integrity checkEPSS 0.3%CVE-2026-59644HIGHMLS hash-ratchet honours arbitrary 32-bit generation counter from senderEPSS 0.3%CVE-2026-14682HIGHPossible OOM from unbounded up-front allocation on a definite-length readEPSS 0.3%