3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.bouncycastle:bctls-fips is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.9
CVE-2024-34447
Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
MEDIUM 5.9
CVE-2024-30171
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
UNKNOWN
CVE-2025-9341
Bouncy Castle for Java has Uncontrolled Resource Consumption Vulnerability
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes