Vulnerabilidades em Legion of the Bouncy Castle Inc.
48 resultadosAnálise Vexday
A Legion of the Bouncy Castle Inc. apresenta 13 vulnerabilidades catalogadas, com apenas 1 crítica e nenhuma sob ataque ativo no momento. A fraqueza dominante (CWE-400: Uncontrolled Resource Consumption) sugere problemas de negação de serviço, e o ritmo recente de 2 publicações em 90 dias indica atividade contínua de descoberta, mas sem pressão imediata de exploração em campo.
CVE-2026-12860HIGHRSA PKCS#1 verification skips last two hash bytes in NULL-omitted pathEPSS 0.2%CVE-2025-9340NONEnative encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output.EPSS 0.2%CVE-2026-8149MEDIUMGCM chunking can lead to bad tag exception on decryptionEPSS 0.2%CVE-2025-9341MEDIUMGarbage collection can delay for AES CBC Native support, resulting in heap exhaustionEPSS 0.2%CVE-2025-12194MEDIUMUncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules)EPSS 0.2%CVE-2026-12802HIGHCMS AuthEnvelopedData fails to enforce tag-length on decryptionEPSS 0.1%CVE-2025-9092LOWHybrid Module Deployment in Multi-JVM Environments Leading to Resource ExhaustionEPSS 0.1%CVE-2026-15997LOWNative ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow in a crafted encoded stateEPSS 0.1%