mirrored from https://www.bouncycastle.org/repositories/bc-java
-
Notifications
You must be signed in to change notification settings - Fork 1.3k
CVE critical high 1.85
David Hook edited this page Oct 2, 2026
·
1 revision
The 4 Critical and 22 High severity CVEs from the 32 addressed in BC 1.85 (see CVE-summary-1.85.md for the full set, including Medium). Ordered by CVSS 4.0 base score, most serious first. Details are taken from the per-CVE JSON records in this directory.
-
CVSS 4.0: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-295 Improper Certificate Validation
- Affected: BC-JAVA 1.66 – < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bc-fips 2.0.0 – < 2.0.2; BC-FJA bc-fips 2.1.0 – < 2.1.3
-
Module / classes: prov —
ProvOcspRevocationChecker - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058062
- Fix commit: https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7
-
CVSS 4.0: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-297 Improper Validation of Certificate with Host Mismatch
- Affected: BC-JAVA 1.61 – < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bctls-fips 1.0.7 – < 1.0.24; BC-FJA bctls-fips 2.0.0 – < 2.0.24; BC-FJA bctls-fips 2.1.0 – < 2.1.24
-
Module / classes: tls —
HostnameUtil - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059638
- Fix commits: https://github.com/bcgit/bc-java/commit/799bd15320a6310a447863638aa3df64acef829b, https://github.com/bcgit/bc-java/commit/5ac55351cd1a8a7184d41c96a7ee87df0770240a
-
CVSS 4.0: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-20 Improper Input Validation
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12
-
Module / classes: core —
DHAgreement - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059650
- Fix commit: https://github.com/bcgit/bc-java/commit/daeaae9d7075d04f40812e68671ebf4c777b5148
-
CVSS 4.0: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-295 Improper Certificate Validation
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bc-fips 1.0.0 – < 1.0.2.7; BC-FJA bc-fips 2.0.0 – < 2.0.2; BC-FJA bc-fips 2.1.0 – < 2.1.3
-
Module / classes: core —
PKIXNameConstraintValidator - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763
- Fix commit: https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-354 Improper Validation of Integrity Check Value
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bcpkix-fips 1.0.0 – < 1.0.12; BC-FJA bcpkix-fips 2.0.0 – < 2.0.12; BC-FJA bcpkix-fips 2.1.0 – < 2.1.12
-
Module / classes: pkix —
AbstractRecipient - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012802
- Fix commit: https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01
CVE-2026-12803 — KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-354 Improper Validation of Integrity Check Value
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12
-
Module / classes: core —
KCCMBlockCipher - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012803
- Fix commits: https://github.com/bcgit/bc-java/commit/697794413ebf7bc5e3fce609a707826ba52981af, https://github.com/bcgit/bc-java/commit/7d79aa76e984da85f2a541cae8ba2ae56e1713bc
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-354 Improper Validation of Integrity Check Value
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12
-
Module / classes: core —
IESEngine - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012816
- Fix commit: https://github.com/bcgit/bc-java/commit/6d9e4bbaee9409713ada167e5f901554cbb084ac
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-354 Improper Validation of Integrity Check Value
- Affected: BC-JAVA 1.74 – < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bcpg-fips 1.0.7 – < 1.0.13; BC-FJA bcpg-fips 2.0.0 – < 2.0.13; BC-FJA bcpg-fips 2.1.0 – < 2.1.13
-
Module / classes: pg —
BcAEADUtil,JceAEADUtil - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012817
- Fix commit: https://github.com/bcgit/bc-java/commit/4b712819846ec944379f4909101abac20f0ad4b0
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-789 Memory Allocation with Excessive Size Value
- Affected: BC-JAVA 1.73 – < 1.85
-
Module / classes: mls —
MLSInputStream - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012852
- Fix commit: https://github.com/bcgit/bc-java/commit/a747038bb5bbd5e29fb2b7607ab38af1fd8d1790
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-347 Improper Verification of Cryptographic Signature
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12
-
Module / classes: core —
RSADigestSigner - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012860
- Fix commit: https://github.com/bcgit/bc-java/commit/ea5970ea9b2fb91d763b904692fd21089ca3e396
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-674 Uncontrolled Recursion
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bc-fips 1.0.0 – < 1.0.2.7; BC-FJA bc-fips 2.0.0 – < 2.0.2; BC-FJA bc-fips 2.1.0 – < 2.1.3
-
Module / classes: core —
ASN1InputStream,LazyEncodedSequence - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9013506
- Fix commit: https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-789 Memory Allocation with Excessive Size Value
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bc-fips 1.0.0 – < 1.0.2.7; BC-FJA bc-fips 2.0.0 – < 2.0.2; BC-FJA bc-fips 2.1.0 – < 2.1.3; BC-FJA bctls-fips 1.0.0 – < 1.0.24
-
Module / classes: core —
DefiniteLengthInputStream - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9014682
- Fix commit: https://github.com/bcgit/bc-java/commit/37094e504ef50cf9ce4e0fb9e5105d495ff5c2d2
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-407 Inefficient Algorithmic Complexity
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bc-fips 1.0.0 – < 1.0.2.7; BC-FJA bc-fips 2.0.0 – < 2.0.2; BC-FJA bc-fips 2.1.0 – < 2.1.3
-
Module / classes: core —
IETFUtils - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058059
- Fix commit: https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-789 Memory Allocation with Excessive Size Value
- Affected: BC-JAVA 1.65 – < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bc-fips 2.0.0 – < 2.0.2; BC-FJA bc-fips 2.1.0 – < 2.1.3
-
Module / classes: core —
HSSPublicKeyParameters,HSSSignature,LMSPublicKeyParameters - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058060
- Fix commits: https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276, https://github.com/bcgit/bc-java/commit/6c9f30b3fdaa3f2140809278caebbffc55920922
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-354 Improper Validation of Integrity Check Value
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bc-fips 1.0.0 – < 1.0.2.7; BC-FJA bc-fips 2.0.0 – < 2.0.2; BC-FJA bc-fips 2.1.0 – < 2.1.3
-
Module / classes: core —
CCMBlockCipher,KCCMBlockCipher,KGCMBlockCipher - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058061
- Fix commits: https://github.com/bcgit/bc-java/commit/cd4a5ab3ad619ff03c7767c1b8b19d5dea2970af, https://github.com/bcgit/bc-java/commit/08d675106bb663ddcc6ec0a4af6f6f62f512697b
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-347 Improper Verification of Cryptographic Signature
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bcpkix-fips 1.0.0 – < 1.0.12; BC-FJA bcpkix-fips 2.0.0 – < 2.0.12; BC-FJA bcpkix-fips 2.1.0 – < 2.1.12
-
Module / classes: pkix —
CMSSignedData - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059639
- Fix commit: https://github.com/bcgit/bc-java/commit/99ddc6dcc6782e6a76b0dd587c77e62eb7096ad0
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-203 Observable Discrepancy
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bcpg-fips 1.0.0 – < 1.0.13; BC-FJA bcpg-fips 2.0.0 – < 2.0.13; BC-FJA bcpg-fips 2.1.0 – < 2.1.13
-
Module / classes: pg —
PGPEncryptedData,PGPPublicKeyEncryptedData,PGPSessionKeyEncryptedData,PGPSymmetricKeyEncryptedData - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059640
- Fix commit: https://github.com/bcgit/bc-java/commit/6b94b1c146cec1f565d9a85847fae511af77503e
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-345 Insufficient Verification of Data Authenticity
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bcmail-fips 1.0.0 – < 1.0.7; BC-FJA bcmail-fips 2.0.0 – < 2.0.7; BC-FJA bcmail-fips 2.1.0 – < 2.1.7; BC-FJA bcjmail-fips 1.0.4 – < 1.0.7; BC-FJA bcjmail-fips 2.0.0 – < 2.0.7; BC-FJA bcjmail-fips 2.1.0 – < 2.1.7
-
Module / classes: mail —
SignedMailValidator - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059641
- Fix commits: https://github.com/bcgit/bc-java/commit/2f81b22d559b3a1b026388e1ca78dd547384def8, https://github.com/bcgit/bc-java/commit/fd89fe918b37fea1c71e95fae50284a325b09721
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-354 Improper Validation of Integrity Check Value
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bcpkix-fips 1.0.0 – < 1.0.12; BC-FJA bcpkix-fips 2.0.0 – < 2.0.12; BC-FJA bcpkix-fips 2.1.0 – < 2.1.12
-
Module / classes: pkix —
RecipientInformation - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059642
- Fix commit: https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-347 Improper Verification of Cryptographic Signature
- Affected: BC-JAVA 1.81 – < 1.85; BC-FJA bcpg-fips 2.0.12 – < 2.0.13
-
Module / classes: pg —
OpenPGPMessageInputStream - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059643
- Fix commit: https://github.com/bcgit/bc-java/commit/d3f8cc408b4a36d28e5a410c93436fe3d0fe726b
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-834 Excessive Iteration
- Affected: BC-JAVA 1.73 – < 1.85
-
Module / classes: mls —
GroupKeySet - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059644
- Fix commit: https://github.com/bcgit/bc-java/commit/610d8757d855afe197df0de6d831cb75c81e3b9f
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-674 Uncontrolled Recursion
- Affected: BC-JAVA 1.70 – < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bcutil-fips 2.0.0 – < 2.0.7; BC-FJA bcutil-fips 2.1.0 – < 2.1.7
-
Module / classes: util —
OERInputStream - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059645
- Fix commit: https://github.com/bcgit/bc-java/commit/822b2478b131097368a56290f5728e28dd042989
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-789 Memory Allocation with Excessive Size Value
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bctls-fips 1.0.0 – < 1.0.24; BC-FJA bctls-fips 2.0.0 – < 2.0.24; BC-FJA bctls-fips 2.1.0 – < 2.1.24
-
Module / classes: tls —
DTLSReliableHandshake - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059646
- Fix commits: https://github.com/bcgit/bc-java/commit/2ea38942c7917f6d7ab4de93d8a5336d021df0d9, https://github.com/bcgit/bc-java/commit/2d98721e71bbd822ffa0f84e088eea645cf679fa
-
CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-789 Memory Allocation with Excessive Size Value
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12; BC-FJA bcpg-fips 1.0.0 – < 1.0.13; BC-FJA bcpg-fips 2.0.0 – < 2.0.13; BC-FJA bcpg-fips 2.1.0 – < 2.1.13
-
Module / classes: pg —
UserAttributeSubpacketInputStream - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059649
- Fix commit: https://github.com/bcgit/bc-java/commit/a43c40dc12c3e1c6cbd03c83fe30aaec4029b824
-
CVSS 4.0: 7.1 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-789 Memory Allocation with Excessive Size Value
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12
-
Module / classes: prov —
BcKeyStoreSpi - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012185
- Fix commit: https://github.com/bcgit/bc-java/commit/7bbd7fe5f44132e5b6140a2914435c12430eeb3d
-
CVSS 4.0: 7.1 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber - CWE: CWE-326 Inadequate Encryption Strength
- Affected: BC-JAVA < 1.85; BC-LTS-JAVA 2.73.0 – < 2.73.12
-
Module / classes: prov —
BcKeyStoreSpi - Advisory: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059651
- Fix commit: https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2