13 Total advisories
13 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.bouncycastle:bcprov-jdk15to18 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2025-14813
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
UNKNOWN
CVE-2026-5598
Bouncy Castle Has Covert Timing Channel Vulnerability
UNKNOWN
CVE-2026-0636
Bouncy Castle has an LDAP injection
MEDIUM 5.9
CVE-2024-34447
Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
MEDIUM 5.9
CVE-2024-30171
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
MEDIUM 5.3
CVE-2024-29857
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
MEDIUM 5.1
CVE-2020-15522
Timing based private key exposure in Bouncy Castle
UNKNOWN
CVE-2025-8885
Bouncy Castle for Java on All (API modules) allows Excessive Allocation
MEDIUM 5.3
CVE-2024-30172
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
MEDIUM 5.3
CVE-2023-33201
Bouncy Castle For Java LDAP injection vulnerability
MEDIUM 5.5
CVE-2023-33202
Bouncy Castle Denial of Service (DoS)
MEDIUM 5.3
CVE-2020-26939
Observable Differences in Behavior to Error Inputs in Bouncy Castle
HIGH 8.1
CVE-2020-28052
Logic error in Legion of the Bouncy Castle BC Java
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes