Bc Lts Java Bouncycastle Bc Lts Java

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Bouncycastle Bc Lts Java.

By the Year

In 2026 there have been 1 vulnerability in Bouncycastle Bc Lts Java with an average score of 9.3 out of ten.

Year Vulnerabilities Average Score
2026 1 9.30

It may take a day or so for new Bc Lts Java vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Bouncycastle Bc Lts Java Security Vulnerabilities

Bouncy Castle JSSE HV CN-Fallback default enabled CVE-2026-59638 (pre-1.85)
CVE-2026-59638 9.3 - Critical - August 03, 2026

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

Improper Validation of Certificate with Host Mismatch

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Bouncycastle Bc Lts Java or by Bouncycastle? Click the Watch button to subscribe.

subscribe