CVE-2026-13506High· 7.5▾ TwilightIn Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X seri…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
bc-java < 1.85bouncy_castle_for_java_lts <= 2.73.11fips_java_api >= 1.0.0, < 1.0.2.7fips_java_api >= 2.0.0, < 2.0.2fips_java_api >= 2.1.0, < 2.1.3Upgrade past the affected range:
bc-java 1.85fips_java_api 2.1.3Affected packages:
org.bouncycastle:bcprov-jdk18on < 1.85org.bouncycastle:bc-fips < 1.0.2.7org.bouncycastle:bc-fips >= 2.0.0, < 2.0.2org.bouncycastle:bc-fips >= 2.1.0, < 2.1.3org.bouncycastle:bcprov-lts8on < 2.73.12org.bouncycastle:bcprov-jdk15to18 < 1.85Patched in:
org.bouncycastle:bcprov-jdk18on 1.85org.bouncycastle:bc-fips 1.0.2.7org.bouncycastle:bc-fips 2.0.2org.bouncycastle:bc-fips 2.1.3org.bouncycastle:bcprov-lts8on 2.73.12org.bouncycastle:bcprov-jdk15to18 1.85Source: https://github.com/advisories/GHSA-qp49-qgx5-5m26
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-14682High· 7.5In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read
CVE-2026-13586High· 7.5In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)
CVE-2026-59643High· 7.5In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored
CVE-2026-93687High· 7.5braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards
CVE-2026-73566High· 7.5node-tar is a tar archive manipulation library for Node.js
CVE-2026-66274High· 7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35…