Bouncycastle Bouncy Castle For Java
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Bouncycastle Bouncy Castle For Java.
By the Year
In 2026 there have been 0 vulnerabilities in Bouncycastle Bouncy Castle For Java. Bouncy Castle For Java did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 1 | 5.50 |
It may take a day or so for new Bouncy Castle For Java vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Bouncycastle Bouncy Castle For Java Security Vulnerabilities
Bouncy Castle Java DoS via PEMParser (v<1.73)
CVE-2023-33202
5.5 - Medium
- November 23, 2023
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.)
Resource Exhaustion
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Bouncycastle Bouncy Castle For Java or by Bouncycastle? Click the Watch button to subscribe.