Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. (CVE-2026-58060)CVE-2026-58060
0

Bouncy Castle for Java versions before 1.85 have an unbounded HSS public-key level count, which can lead to excessive memory allocation during verification. This vulnerability also affects Bouncy Castle for Java LTS versions before 2.73.12 and Bouncy Castle for Java FIPS versions before 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Join the discussion
In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. (CVE-2026-58059)CVE-2026-58059
0

Bouncy Castle for Java versions before 1.85 and certain LTS and FIPS versions have a vulnerability causing quadratic-time escaping when stringifying X.500 distinguished names. This performance issue can lead to high resource consumption during processing. The vulnerability is identified as CWE-407 and is rated with high severity.

Join the discussion
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). (CVE-2026-12803)CVE-2026-12803
0

Bouncy Castle for Java versions before 1.85 and LTS versions before 2.73.12 have a vulnerability in the KCCMBlockCipher MAC implementation where the nonce is not bound when Additional Authenticated Data (AAD) is absent. This flaw allows a cross-nonce AEAD forgery attack, undermining the integrity guarantees of the cipher.

Join the discussion
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. (CVE-2026-12816)CVE-2026-12816
0

A vulnerability exists in Bouncy Castle for Java before version 1.85 and in the LTS version before 2.73.12, where the IESEngine stream-mode MAC can be forged due to a length-dependent key derivation function (KDF) split. This issue is tracked as CVE-2026-12816 and is classified under CWE-354 (Improper Validation of Integrity Check Value).

Join the discussion
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. (CVE-2026-8763)CVE-2026-8763
0

A critical vulnerability exists in Bouncy Castle for Java before version 1.85 that allows bypassing Name Constraints via a trailing dot in rfc822Name and URI fields. This issue also affects Bouncy Castle for Java LTS versions before 2.73.12 and Bouncy Castle for Java FIPS versions before 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series), and 2.1.3 (2.1.X series). The vulnerability is identified as CVE-2026-8763 and relates to improper validation of name constraints, classified under CWE-295. No patch links are provided, and no known exploits are reported in the wild.

Join the discussion
In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. (CVE-2026-12817)CVE-2026-12817
0

Bouncy Castle for Java versions before 1.85 have a vulnerability in OpenPGP AEAD decryption where the final authentication tag is skipped on chunk-aligned data. This flaw also affects Bouncy Castle for Java LTS before 2.73.12 and Bouncy Castle for Java FIPS versions prior to bcpg-fips 1.0.13, 2.0.13, and 2.1.13 in their respective series. The issue can lead to improper verification of encrypted data integrity.

Join the discussion
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). (CVE-2026-13586)CVE-2026-13586
0

A vulnerability in Bouncy Castle for Java prior to version 1.85 allows an attacker to exploit the PKCS#12 MAC and bag-decryption KDF iteration-count bound, potentially causing a denial of service (DoS). This issue also affects Bouncy Castle for Java LTS versions before 2.73.12 and various versions of Bouncy Castle for Java FIPS. The vulnerability is categorized under CWE-770, which relates to allocation of resources without limits or throttling. No known exploits are reported in the wild, and no patch information is currently available.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:maven/org.bouncycastle/bcprov-jdk15on-lts
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses