Bouncy Castle For Java Bouncycastle Bouncy Castle For Java

Do you want an email whenever new security vulnerabilities are reported in Bouncycastle Bouncy Castle For Java?

By the Year

In 2024 there have been 0 vulnerabilities in Bouncycastle Bouncy Castle For Java . Last year Bouncy Castle For Java had 1 security vulnerability published. Right now, Bouncy Castle For Java is on track to have less security vulnerabilities in 2024 than it did last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 1 5.50
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Bouncy Castle For Java vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Bouncycastle Bouncy Castle For Java Security Vulnerabilities

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class

CVE-2023-33202 5.5 - Medium - November 23, 2023

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.)

Resource Exhaustion

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Bouncycastle Bouncy Castle For Java or by Bouncycastle? Click the Watch button to subscribe.

subscribe