VYPR

Bouncy Castle for Java FIPS bc-fips

by Legion Of The Bouncy Castle Inc.

Source repositories

CVEs (22)

  • CVE-2026-59648Aug 4, 2026
    risk 0.00cvss epss

    In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and…

  • CVE-2026-59649Aug 4, 2026
    risk 0.00cvss epss

    In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X…

Page 2 of 2