Bouncycastle Bcpkix-fips — known CVE vulnerabilities
Every CVE whose affected-product data names Bouncycastle Bcpkix-fips, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (5)
CVE-2026-15055 — CVSS 8.2 (high): In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy…
CVE-2026-12802 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy…
CVE-2026-59639 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy…
CVE-2026-59642 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects…
CVE-2026-59647 — CVSS 5.3 (medium): In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for…