VulnSea

BouncyCastle.Cryptography vulnerabilities

CVEs whose affected-version data names the BouncyCastle.Cryptography package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

21 CVEsRSS

CVE-2026-63572High· 7.1
today

Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc

Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through …

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63571High· 8.7
today

Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also used by PkixAttrCertPathBuilder) in Legion of the Bouncy Castle Inc

Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also used by PkixAttrCertPathBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote att…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63570High· 7.1
today

Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc

Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an application that loads it and requests a ke…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63575High· 7.1
today

Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc

Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted priva…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63574High· 8.7
today

Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc

Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc. bc-csharp befo…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63573High· 8.2
today

Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc

Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who holds a captured CMS EnvelopedData me…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63578High· 7.1
today

Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc

Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply an encrypted private key…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63577High· 8.2
today

Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc

Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63576High· 8.2
today

Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc

Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to obtain certificates with chosen su…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-103603High· 8.7
today

Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc

Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an H…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-103601High· 8.2
today

Release of unverified plaintext in the CCM (CcmBlockCipher) and DSTU 7624 CCM (KCcmBlockCipher) AEAD modes in Legion of the Bouncy Castle Inc

Release of unverified plaintext in the CCM (CcmBlockCipher) and DSTU 7624 CCM (KCcmBlockCipher) AEAD modes in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker to obtain decryptions of ciphertexts of their …

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-103600High· 8.7
today

Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc

Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service via a crafted ASN.1 encoding …

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-103604High· 8.7
today

Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc

Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to c…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-103602High· 8.2
today

Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc

Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-constrained intermediate CA to have certif…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-16001High· 8.2
today

Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed without a block cipher) in Legion of the Bouncy Castle Inc

Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed without a block cipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote atta…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-16000High· 8.7
today

Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc

Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can observe encrypted messages of known or chosen content to forge ci…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-15999High· 8.2
today

Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc

Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to modify CCM-encrypted content without d…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63566High· 8.7
today

Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc

Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated DTLS peer to cause a denial …

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63567High· 8.2
today

Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc

Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption unde…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63568High· 8.7
today

Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc

Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of serv…

▾ TwilightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
CVE-2026-63569Critical· 9.1
today

Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc

Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attack…

▾ MidnightLegion of the Bouncy Castle Inc. · BouncyCastle.Cryptographyvia NVD
BouncyCastle.Cryptography vulnerabilities (CVEs) · VulnSea