4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.bouncycastle:bcprov-jdk16 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.1
CVE-2020-15522
Timing based private key exposure in Bouncy Castle
MEDIUM 5.5
CVE-2023-33202
Bouncy Castle Denial of Service (DoS)
MEDIUM 5.3
CVE-2020-26939
Observable Differences in Behavior to Error Inputs in Bouncy Castle
HIGH 8.1
CVE-2020-28052
Logic error in Legion of the Bouncy Castle BC Java
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes