9 Total advisories
9 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.bouncycastle:bc-fips is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.5
CVE-2022-45146
Garbage collection issue in BC-FJA in Java 13 and later
UNKNOWN
CVE-2025-9092
Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability
MEDIUM 5.3
CVE-2024-29857
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
MEDIUM 5.1
CVE-2020-15522
Timing based private key exposure in Bouncy Castle
UNKNOWN
CVE-2025-8885
Bouncy Castle for Java on All (API modules) allows Excessive Allocation
UNKNOWN
CVE-2025-12194
Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
UNKNOWN
CVE-2025-9340
Bouncy Castle for Java has Out-of-Bounds Write Vulnerability
UNKNOWN
CVE-2025-9341
Bouncy Castle for Java has Uncontrolled Resource Consumption Vulnerability
MEDIUM 5.3
CVE-2020-26939
Observable Differences in Behavior to Error Inputs in Bouncy Castle
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes