3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.bouncycastle:bcpkix-jdk18on is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2025-8916
Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
UNKNOWN
CVE-2026-5588
Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
MEDIUM 5.5
CVE-2023-33202
Bouncy Castle Denial of Service (DoS)
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes