Bouncycastle Bctls-fips — known CVE vulnerabilities
Every CVE whose affected-product data names Bouncycastle Bctls-fips, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (3)
CVE-2026-14682 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects…
CVE-2026-59646 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects…
CVE-2026-59638 — CVSS 6.5 (medium): In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also…