Bouncy Castle vulnerabilities
19 CVEs tracked
Bouncy Castle appears in recent reports with multiple critical vulnerabilities in its Java library. Key themes include flaws in OpenPGP, DTLS, X.509 Name Constraints, BKS keystore, and ML-KEM modules in unpatched versions. Reports specifically highlight CVE-2024-14041 (cryptographic calculation error in ML-KEM routines), CVE-2026-8763 (Name Constraints bypass), CVE-2026-59652 (LDAP filter injection), CVE-2026-59649 (memory limitation issue in OpenPGP), and CVE-2026-59646 (buffer allocation in DTLS handshake). Defenders should urgently update to patched Bouncy Castle versions 1.85 and corresponding FIPS/LTS series, paying close attention to components used in OpenPGP, PKI certificate validation, and LDAP operations.
Azərbaycanca: Bouncy Castle biblioqotekası son hesabatlarda Java kitabxanasının bir neçə kritik zəifliyi ilə gündəmə gəlir. Əsas mövzular OpenPGP, DTLS, X.509 Name Constraints, BKS keystore və ML-KEM modullarında yamaq edilməmiş versiyalardakı zəifliklərdir. Hesabatlarda xüsusilə CVE-2024-14041 (ML-KEM rutinlərində kriptoqrafik hesablama xətası), CVE-2026-8763 (Name Constraints bypass), CVE-2026-59652 (LDAP filter injection), CVE-2026-59649 (OpenPGP-də yaddaş limitasiyası problemi) və CVE-2026-59646 (DTLS handshake-də bufer ayrılması) kimi zəifliklər vurğulanır. Müdafiəçilər Bouncy Castle kitabxanasının 1.85 və FIPS/LTS seriyalarındakı müvafiq yamaqlı versiyalarına təcili yeniləmə etməli, xüsusilə OpenPGP, PKI sertifikat validasiyası və LDAP əməliyyatlarında istifadə olunan komponentlərə diqqət yetirməlidir.
This vendor's CVEs19
- CVE-2026-59652EPSS 0.36%
- CVE-2026-59651EPSS 0.18%
- CVE-2026-59649EPSS 0.28%
- CVE-2026-59648EPSS 0.27%
- CVE-2026-59646EPSS 0.35%
- CVE-2026-59645EPSS 0.31%
- CVE-2026-59642EPSS 0.15%
- CVE-2026-59641EPSS 0.15%
- CVE-2026-59640EPSS 0.22%
- CVE-2026-59639EPSS 0.16%
- CVE-2026-58063EPSS 0.35%
- CVE-2026-58062EPSS 0.21%
- CVE-2026-58059EPSS 0.35%
- CVE-2026-15055EPSS 0.27%
- CVE-2026-13505EPSS 0.25%
- CVE-2026-12185EPSS 0.23%
- CVE-2026-8798EPSS 0.33%
- CVE-2026-8763EPSS 0.35%
- CVE-2024-14041EPSS 0.34%
This hub is built from skopnix's own reporting on Bouncy Castle: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.