Bc Fja Bouncycastle Bc Fja

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Bouncycastle Bc Fja.

By the Year

In 2026 there have been 1 vulnerability in Bouncycastle Bc Fja with an average score of 9.3 out of ten.

Year Vulnerabilities Average Score
2026 1 9.30

It may take a day or so for new Bc Fja vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Bouncycastle Bc Fja Security Vulnerabilities

Bouncy Castle JSSE HV CN-Fallback default enabled CVE-2026-59638 (pre-1.85)
CVE-2026-59638 9.3 - Critical - August 03, 2026

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

Improper Validation of Certificate with Host Mismatch

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Bouncycastle Bc Fja or by Bouncycastle? Click the Watch button to subscribe.

subscribe