Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/bcprov

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-12185 is a high severity vulnerability in Legion of the Bouncy Castle Inc.'s BC-JAVA library. It involves memory allocation with excessive size values in BKS/UBER keystore implementations before integrity checks are performed. This affects versions prior to 1.85 and versions from 2.73.0 up to but not including 2.73.12.

Join the discussion

CVE-2026-13506 is a high severity vulnerability in Bouncy Castle for Java (BC-JAVA) involving uncontrolled recursion due to a Lazy ASN.1 sequence forcing that resets the nesting-depth guard. This affects versions before 1.85 and certain LTS and FIPS versions prior to specified fixed releases. The vulnerability has a CVSS 4.0 score of 8.7, indicating a significant impact if exploited. No official patch or remediation level is currently confirmed from the vendor advisory. No known exploits are reported in the wild.

Join the discussion

CVE-2026-59650 is a critical vulnerability in Legion of the Bouncy Castle Inc.'s BC-JAVA library affecting versions before 1.85 and LTS versions from 2.73.0 up to but not including 2.73.12. The flaw involves improper input validation in the MTI/A0 Diffie-Hellman agreement process, where an unvalidated peer value is exponentiated. This can lead to severe cryptographic failures. The vulnerability has a high CVSS 4.0 score of 9.3, indicating network exploitable with no privileges or user interaction required. No official patch or remediation guidance is currently confirmed from the vendor advisory. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-59651 is a vulnerability in Bouncy Castle for Java (BC-JAVA) affecting versions before 1.85 and LTS versions from 2.73.0 up to but not including 2.73.12. The issue involves the BKS keystore accepting a legacy version that uses a 16-bit integrity MAC key, which is considered inadequate encryption strength. This weakness could potentially undermine the integrity protection of the keystore data.

Join the discussion

CVE-2026-59652 is an LDAP injection vulnerability in the Bouncy Castle for Java library (BC-JAVA) affecting versions before 1.85. The issue occurs in the legacy jdk1.4 LDAPStoreHelper component, where improper neutralization of special elements in LDAP queries allows injection. This vulnerability has a medium severity with a CVSS score of 6.9.

Join the discussion

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.

Join the discussion

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

Join the discussion

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:github/bcprov
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses