Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-13505: CWE-772 Missing Release of Resource after Effective Lifetime in Legion of the Bouncy Castle Inc. BC-FJACVE-2026-13505 0 Bouncy Castle for Java FIPS (BC-FJA) versions before 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series), and 2.1.3 (2.1.X series) use Object.finalize for zeroising sensitive key material. Finalization timing and order are unspecified and rely on a single finalizer thread, which can cause delays in zeroisation and lead to sensitive key material remaining in memory longer than intended. This behavior can cause increased memory usage and potential OutOfMemoryError under load. The issue affects Java versions later than 11 where finalization is deprecated. The zeroisation mechanism has been updated to use java.lang.ref.Cleaner on Java 9 and later, avoiding reliance on finalization. Bouncy Castle for Java (bcprov) and Bouncy Castle for Java LTS are not affected as they do not use this finalizer-based zeroisation. Join the discussion | GCVE Database | 08/08/2026, 00:59:40 UTC Added: 08/08/2026, 14:51:51 UTC |
CVE-2026-8798: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Legion of the Bouncy Castle Inc. BC-FJACVE-2026-8798 0 A vulnerability in Bouncy Castle for Java FIPS (BC-FJA) before version 2.1.3 causes the native entropy source on Intel platforms to retry CPU entropy instructions indefinitely if they fail persistently. This results in an uninterruptible hang in the JNI seeding routine, potentially causing denial of service for applications relying on this entropy source. The issue is fixed by bounding retry attempts and throwing an exception on exhaustion. Bouncy Castle for Java (bcprov) and earlier FIPS series 1.0.X and 2.0.X are not affected. Join the discussion | GCVE Database | 08/08/2026, 00:50:56 UTC Added: 08/08/2026, 14:51:50 UTC |
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. (CVE-2026-14682)CVE-2026-14682 0 Bouncy Castle for Java versions prior to 1.85 and certain LTS and FIPS versions contain a vulnerability that may cause an out-of-memory (OOM) condition due to unbounded memory allocation during a definite-length read operation. This issue affects multiple Bouncy Castle Java variants including LTS before 2.73.12, BC-FJA before 1.0.2.7, 2.0.2, and 2.1.3, and bctls-fips before 1.0.24. The vulnerability is classified under CWE-789 (Uncontrolled Memory Allocation). Join the discussion | GCVE Database | 08/03/2026, 06:31:44 UTC Added: 08/03/2026, 21:22:11 UTC |
Showing 1 to 3 of 3 results