Bouncycastle Bcutil-fips — known CVE vulnerabilities
Every CVE whose affected-product data names Bouncycastle Bcutil-fips, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (1)
CVE-2026-59645 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also…