org.bouncycastle:bcprov-lts8on
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.bouncycastle:bcprov-lts8onpage 1 of 1
- CVE-2024-34447HIGHCVSS 7.5EG 7.5fixed in 2.73.62024-05-03
vulnerable: 2.73.0 ... 2.73.5 (6 versions)
An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an…
- CVE-2026-13506HIGHCVSS 7.5EG 7.5fixed in 2.73.122026-08-03
vulnerable: 2.73.0 ... 2.73.9 (12 versions)
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series…
- CVE-2026-8149MEDIUMCVSS 5.1EG 5.1fixed in 2.73.112026-05-08
vulnerable: 2.73.0 ... 2.73.9 (11 versions)
A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program file…
- CVE-2026-8763CRITICALCVSS 9.1EG 9.1fixed in 2.73.122026-08-03
vulnerable: 2.73.0 ... 2.73.9 (12 versions)
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.…
Check whether org.bouncycastle:bcprov-lts8on is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.bouncycastle:bcprov-lts8on CVEs against the assets you own.
Book a Demo →