org.bouncycastle:bc-fips
Maven14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.bouncycastle:bc-fipspage 1 of 1
- CVE-2020-15522MEDIUMCVSS 5.9EG 5.9fixed in 1.0.2.12021-05-20
vulnerable: 1.0.0, 1.0.1, 1.0.2
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able…
- CVE-2020-26939MEDIUMCVSS 5.3EG 5.3fixed in 1.0.22020-11-02
vulnerable: 1.0.0, 1.0.1
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.cry…
- CVE-2022-45146MEDIUMCVSS 5.5EG 5.5fixed in 1.0.2.42022-11-21
vulnerable: 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, 1.0.2.3
An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the …
- CVE-2024-29857HIGHCVSS 7.5EG 7.5fixed in 1.0.2.52024-05-14
vulnerable: 1.0.0 ... 1.0.2.4 (6 versions)
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can …
- CVE-2025-12194MEDIUMCVSS 5.9EG 5.9fixed in 2.1.22025-10-24
vulnerable: 2.1.0, 2.1.1
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) al…
- CVE-2025-8885MEDIUMCVSS 6.3EG 6.3fixed in 1.0.2.6 or 2.0.1, by version range2025-08-12
vulnerable: 2.0.0
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerabil…
- CVE-2025-9092LOWCVSS 1.0EG 1.0fixed in 2.1.12025-08-16
vulnerable: 2.1.0
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycast…
- CVE-2025-9340UnratedEG not assessedfixed in 2.1.12025-08-22
vulnerable: 2.1.0
Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects…
- CVE-2025-9341MEDIUMCVSS 5.9EG 5.9fixed in 2.1.12025-08-22
vulnerable: 2.1.0
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) al…
- CVE-2026-13505HIGHCVSS 8.7EG 8.7fixed in 1.0.2.7, 2.0.2 or 2.1.3, by version range2026-08-08
vulnerable: 2.1.0, 2.1.1, 2.1.2
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and the PBKD …
- CVE-2026-13506HIGHCVSS 7.5EG 7.5fixed in 1.0.2.7, 2.0.2 or 2.1.3, by version range2026-08-03
vulnerable: 2.1.0, 2.1.1, 2.1.2
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series…
- CVE-2026-8149MEDIUMCVSS 5.1EG 5.12026-05-08
vulnerable: 2.1.0, 2.1.1, 2.1.2
A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program file…
- CVE-2026-8763CRITICALCVSS 9.1EG 9.1fixed in 1.0.2.7, 2.0.2 or 2.1.3, by version range2026-08-03
vulnerable: 2.1.0, 2.1.1, 2.1.2
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.…
- CVE-2026-8798HIGHCVSS 8.7EG 8.7fixed in 2.1.32026-08-08
vulnerable: 2.1.0, 2.1.1, 2.1.2
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound. RDSEED and RDRAND report failure through their carry flag, and the JNI …
Check whether org.bouncycastle:bc-fips is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.bouncycastle:bc-fips CVEs against the assets you own.
Book a Demo →