VulnSea

bouncycastle has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 6. The median CVSS is 7.5 (high). None have a confirmed exploitation report. Most affected products: bc-java (4), org.bouncycastle:bc-fips (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
6 prev 0

Products

  • bc-java 4
  • org.bouncycastle:bc-fips 2
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

bouncycastle vulnerabilities

CVEs affecting bouncycastle, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-8798High
1mo ago

Bouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound

Bouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound

Twilightbouncycastle · org.bouncycastle:bc-fipsEPSS 0.33%via GHSA
CVE-2026-13505High
1mo ago

Bouncy Castle: Zeroisation of sensitive key material on garbage collection relies on finalization.

Bouncy Castle: Zeroisation of sensitive key material on garbage collection relies on finalization.

Twilightbouncycastle · org.bouncycastle:bc-fipsEPSS 0.25%via GHSA
CVE-2026-14682High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips …

Twilightbouncycastle · bc-javaEPSS 0.31%via NVD
CVE-2026-13586High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.…

Twilightbouncycastle · bc-javaEPSS 0.35%via NVD
CVE-2026-13506High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X seri…

Twilightbouncycastle · bc-javaEPSS 0.31%via NVD
CVE-2026-59643High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.

Twilightbouncycastle · bc-javaEPSS 0.16%via NVD
bouncycastle vulnerabilities (CVEs) · VulnSea