vciy

CVEs we hold for Legion

Records whose assigning authority named Legion as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8798Native entropy source retries the CPU entropy instructions without limitLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-8763Name Constraints bypass via trailing dot in rfc822Name and URILegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-8149GCM chunking can lead to bad tag exception on decryptionLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59652LDAP filter injection in legacy jdk1.4 LDAPStoreHelperLegion of the Bouncy Castle Inc. BC-JAVA
CVE-2026-59651BKS keystore accepts legacy version with 16-bit integrity MAC keyLegion of the Bouncy Castle Inc. BC-LTS-JAVA
CVE-2026-59650MTI/A0 DH agreement exponentiates unvalidated peer valueLegion of the Bouncy Castle Inc. BC-LTS-JAVA
CVE-2026-59649OpenPGP user-attribute subpacket length bounded only by JVM max memoryLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59648OpenPGP Argon2 S2K honours attacker-chosen memory and passesLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59647CRMF/CMP password-MAC honours unbounded iteration countLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59646DTLS handshake reassembler allocates buffer from unchecked 24-bit lengthLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59645OER parser recurses without depth limit on self-referential IEEE 1609.2 schemaLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59644MLS hash-ratchet honours arbitrary 32-bit generation counter from senderLegion of the Bouncy Castle Inc. BC-JAVA
CVE-2026-59643OpenPGP inline-signature policy failures silently ignoredLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59642CMS AuthenticatedData content not bound to MAC when authAttrs presentLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59641S/MIME validator trusts signer-asserted signingTime for path validationLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59640OpenPGP CFB quick-check oracle active on symmetric/session-key pathsLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59639CMS verifySignatures returns true for SignedData with zero signersLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-59638JSSE hostname verifier CN-fallback enabled by default despite documented opt-inLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-58063BCFKS keystore load honours unbounded KDF cost from untrusted fileLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-58062Stapled OCSP response accepted without binding to the checked certificateLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-58061CCM-family modes write plaintext to caller buffer before tag checkLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-58060HSS public-key level count unbounded, enabling huge allocation on verifyLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-58059Quadratic-time escaping when stringifying X.500 distinguished namesLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-5598Non-constant time comparisons risk private key leakage in FrodoKEM.Legion of the Bouncy Castle Inc. BC-JAVA
CVE-2026-5588PKIX draft CompositeVerifier accepts empty signature sequence as valid.Legion of the Bouncy Castle Inc. BCPIX-LTS
CVE-2026-3505Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.Legion of the Bouncy Castle Inc. BC-JAVA
CVE-2026-15997Native ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow in a crafted encoded stateLegion of the Bouncy Castle Inc. BC-LTS
CVE-2026-15055PKCS#8 / PBES2 decryptors honour unbounded KDF cost from inputLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-14682Possible OOM from unbounded up-front allocation on a definite-length readLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-13586PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)Legion of the Bouncy Castle Inc. BC-FJA
CVE-2026-13506Lazy ASN.1 sequence forcing resets nesting-depth guardLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-13505Zeroisation of sensitive key material on garbage collection relies on finalizationLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-12860RSA PKCS#1 verification skips last two hash bytes in NULL-omitted pathLegion of the Bouncy Castle Inc. BC-LTS-JAVA
CVE-2026-12852MLS wire decoder allocates attacker-declared opaque length before bounds checkLegion of the Bouncy Castle Inc. BC-JAVA
CVE-2026-12817OpenPGP AEAD decryption skips final tag on chunk-aligned dataLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-12816IESEngine stream-mode MAC forgery via length-dependent KDF splitLegion of the Bouncy Castle Inc. BC-LTS-JAVA
CVE-2026-12803KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)Legion of the Bouncy Castle Inc. BC-LTS-JAVA
CVE-2026-12802CMS AuthEnvelopedData fails to enforce tag-length on decryptionLegion of the Bouncy Castle Inc. BC-FJA
CVE-2026-12185BKS/UBER keystore allocates from untrusted lengths before integrity checkLegion of the Bouncy Castle Inc. BC-LTS-JAVA
CVE-2026-0636LDAP Injection Vulnerability in LDAPStoreHelper.javaLegion of the Bouncy Castle Inc. BC-JAVA
CVE-2025-9341Garbage collection can delay for AES CBC Native support, resulting in heap exhaustionLegion of the Bouncy Castle Inc. Bouncy Castle for Java LTS
CVE-2025-9340native encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output.Legion of the Bouncy Castle Inc. Bouncy Castle for Java
CVE-2025-9092Hybrid Module Deployment in Multi-JVM Environments Leading to Resource ExhaustionLegion of the Bouncy Castle Inc. Bouncy Castle for Java -…
CVE-2025-8916Possible DOS in processing large name constraint structures in PKIXCertPathReveiwerLegion of the Bouncy Castle Inc. BCPKIX FIPS
CVE-2025-8885Possible DOS in processing specially formed ASN.1 Object IdentifiersLegion of the Bouncy Castle Inc. BC-FJA
CVE-2025-14813GOSTCTR implementation unable to process more than 255 blocks correctlyLegion of the Bouncy Castle Inc. BC-JAVA
CVE-2025-12194no title heldLegion of the Bouncy Castle Inc. Bouncy Castle for Java LTS
CVE-2024-14041ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and…Legion of the Bouncy Castle Inc. BC-JAVA
CVE-2018-5382Bouncy Castle BKS-V1 keystore files vulnerable to trivial hash collisionsLegion of the Bouncy Castle Bouncy Castle
CVE-2017-13098BouncyCastle JCE TLS Bleichenbacher/ROBOTLegion of the Bouncy Castle BouncyCastle TLS

50 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.