[NEU] [hoch] Bouncy Castle: Mehrere Schwachstellen
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Bouncy Castle ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2622
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-121850.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-128020.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-128030.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-128160.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-128170.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-128520.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-128600.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-135060.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-135860.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
- Low exploitation riskCVE-2026-146820.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownCVE-2026-14682: In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a de…nvd
- unknownCVE-2026-13586: In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count boun…nvd
- unknownCVE-2026-13506: In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard.…nvd
- unknownCVE-2026-12860: In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NU…nvd
- unknownCVE-2026-12852: In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque len…nvd
- unknownCVE-2026-12817: In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligne…nvd
- unknownCVE-2026-12816: In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent …nvd
- unknownCVE-2026-12803: In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is abs…nvd
- unknownCVE-2026-12802: In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on de…nvd
- unknownCVE-2026-58063: In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from unt…nvd
- unknownCVE-2026-58062: In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the c…nvd
- unknownCVE-2026-58061: In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer befor…nvd
Recent advisories for Bouncy Castle
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-14682: In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a de…nvd · 2026-08-03
- unknownCVE-2026-13586: In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count boun…nvd · 2026-08-03
- unknownCVE-2026-13506: In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard.…nvd · 2026-08-03
- unknownCVE-2026-12860: In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NU…nvd · 2026-08-03
- unknownCVE-2026-12852: In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque len…nvd · 2026-08-03
- unknownCVE-2026-12817: In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligne…nvd · 2026-08-03
More from CERT-Bund (BSI) Security Advisories
- high[NEU] [hoch] rclone: Mehrere Schwachstellen2026-08-03
- medium[NEU] [mittel] N-able N-Central: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen2026-08-03
- high[NEU] [hoch] Wazuh: Mehrere Schwachstellen2026-08-03
- high[NEU] [hoch] IBM App Connect Enterprise: Mehrere Schwachstellen2026-08-03
- high[NEU] [hoch] IBM Langflow Desktop: Mehrere Schwachstellen2026-08-03