Known Vulnerabilities for BCPKIX-FIPS by Legion Of The Bouncy Castle Inc.
Listed below are 10 of the newest known vulnerabilities associated with "BCPKIX-FIPS" by "Legion Of The Bouncy Castle Inc.".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-71892 json | In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.j... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-71889 json | In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReview... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-71888 json | In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm an... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-59647 json | In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bounc... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-59642 json | In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-59639 json | In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also af... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-17508 json | In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters ta... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-15055 json | In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affect... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-12802 json | In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affec... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-5588 json | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pki... | Not Provided | 2026-04-15 | 2026-09-18 |