{"schema_version":1,"title":"org.bouncycastle:bcprov-jdk15on (Maven) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 24 vulnerabilities in org.bouncycastle:bcprov-jdk15on (Maven): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-29857, was published on 14 May 2024.","url":"https://junglewise.ai/threats/technologies/org-bouncycastle-bcprov-jdk15on","json_url":"https://junglewise.ai/threats/technologies/org-bouncycastle-bcprov-jdk15on.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/org-bouncycastle-bcprov-jdk15on","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":24,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2024-29857","cvss":3.1,"epss":0.011,"slug":"cve-2024-29857-bouncy-castle-certificate-parsing-issues-cause-high-cpu-usage","title":"Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.","severity":"low","exploited":false,"published_at":"2024-05-14T15:32:54+00:00","url":"https://junglewise.ai/threats/cve-2024-29857-bouncy-castle-certificate-parsing-issues-cause-high-cpu-usage"},{"cve":"CVE-2024-30171","cvss":3.1,"epss":0.009,"slug":"cve-2024-30171-bouncy-castle-affected-by-timing-side-channel-for-rsa-key","title":"Bouncy Castle affected by timing side-channel for RSA key exchange (\"The Marvin Attack\")","severity":"low","exploited":false,"published_at":"2024-05-14T15:32:54+00:00","url":"https://junglewise.ai/threats/cve-2024-30171-bouncy-castle-affected-by-timing-side-channel-for-rsa-key"},{"cve":"CVE-2024-34447","cvss":5.9,"epss":0.0077,"slug":"cve-2024-34447-bouncy-castle-java-cryptography-api-dns-poisoning-in-bcjsse","title":"Bouncy Castle Java Cryptography API DNS poisoning in BCJSSE","severity":"medium","exploited":false,"published_at":"2024-05-03T18:30:37+00:00","url":"https://junglewise.ai/threats/cve-2024-34447-bouncy-castle-java-cryptography-api-dns-poisoning-in-bcjsse"},{"cve":"CVE-2023-33202","cvss":3.1,"epss":0.0102,"slug":"cve-2023-33202-bouncy-castle-denial-of-service-dos","title":"Bouncy Castle Denial of Service (DoS)","severity":"low","exploited":false,"published_at":"2023-11-23T18:30:33+00:00","url":"https://junglewise.ai/threats/cve-2023-33202-bouncy-castle-denial-of-service-dos"},{"cve":"CVE-2023-33201","cvss":3.1,"epss":0.0077,"slug":"cve-2023-33201-bouncy-castle-for-java-ldap-injection-vulnerability","title":"Bouncy Castle For Java LDAP injection vulnerability","severity":"low","exploited":false,"published_at":"2023-07-05T03:30:23+00:00","url":"https://junglewise.ai/threats/cve-2023-33201-bouncy-castle-for-java-ldap-injection-vulnerability"},{"cve":"CVE-2013-1624","epss":0.0297,"slug":"cve-2013-1624-improper-input-validation-in-bouncy-castle","title":"Improper Input Validation in Bouncy Castle","severity":"info","exploited":false,"published_at":"2022-05-14T02:14:04+00:00","url":"https://junglewise.ai/threats/cve-2013-1624-improper-input-validation-in-bouncy-castle"},{"cve":"CVE-2017-13098","cvss":3,"epss":0.2428,"slug":"cve-2017-13098-observable-discrepancy-in-bouncycastle","title":"Observable Discrepancy in BouncyCastle","severity":"low","exploited":false,"published_at":"2022-05-13T01:14:24+00:00","url":"https://junglewise.ai/threats/cve-2017-13098-observable-discrepancy-in-bouncycastle"},{"cve":"CVE-2018-5382","cvss":3.1,"epss":0.0026,"slug":"cve-2018-5382-improper-validation-of-integrity-check-value-in-bouncy-castle","title":"Improper Validation of Integrity Check Value in Bouncy Castle","severity":"low","exploited":false,"published_at":"2022-05-13T01:01:01+00:00","url":"https://junglewise.ai/threats/cve-2018-5382-improper-validation-of-integrity-check-value-in-bouncy-castle"},{"cve":"CVE-2020-15522","cvss":3.1,"epss":0.0152,"slug":"cve-2020-15522-timing-based-private-key-exposure-in-bouncy-castle","title":"Timing based private key exposure in Bouncy Castle","severity":"low","exploited":false,"published_at":"2021-08-13T15:22:31+00:00","url":"https://junglewise.ai/threats/cve-2020-15522-timing-based-private-key-exposure-in-bouncy-castle"},{"cve":"CVE-2020-28052","cvss":3.1,"epss":0.0723,"slug":"cve-2020-28052-logic-error-in-legion-of-the-bouncy-castle-bc-java","title":"Logic error in Legion of the Bouncy Castle BC Java","severity":"low","exploited":false,"published_at":"2021-04-30T16:14:15+00:00","url":"https://junglewise.ai/threats/cve-2020-28052-logic-error-in-legion-of-the-bouncy-castle-bc-java"},{"cve":"CVE-2020-26939","cvss":3.1,"epss":0.0093,"slug":"cve-2020-26939-observable-differences-in-behavior-to-error-inputs-in-bouncy","title":"Observable Differences in Behavior to Error Inputs in Bouncy Castle","severity":"low","exploited":false,"published_at":"2021-04-22T16:16:49+00:00","url":"https://junglewise.ai/threats/cve-2020-26939-observable-differences-in-behavior-to-error-inputs-in-bouncy"},{"cve":"CVE-2016-1000345","cvss":3,"epss":0.0262,"slug":"cve-2016-1000345-moderate-severity-vulnerability-that-affects-org-bouncycastle","title":"Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15","severity":"low","exploited":false,"published_at":"2018-10-18T18:04:13+00:00","url":"https://junglewise.ai/threats/cve-2016-1000345-moderate-severity-vulnerability-that-affects-org-bouncycastle"},{"cve":"CVE-2016-1000344","cvss":3,"epss":0.0221,"slug":"cve-2016-1000344-in-bouncy-castle-jce-provider-the-dhies-implementation-allowed","title":"In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB mode","severity":"low","exploited":false,"published_at":"2018-10-18T17:43:55+00:00","url":"https://junglewise.ai/threats/cve-2016-1000344-in-bouncy-castle-jce-provider-the-dhies-implementation-allowed"},{"cve":"CVE-2015-7940","epss":0.0482,"slug":"cve-2015-7940-moderate-severity-vulnerability-that-affects-org-bouncycastle","title":"Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15","severity":"info","exploited":false,"published_at":"2018-10-17T16:27:50+00:00","url":"https://junglewise.ai/threats/cve-2015-7940-moderate-severity-vulnerability-that-affects-org-bouncycastle"},{"cve":"CVE-2016-1000352","cvss":3,"epss":0.0221,"slug":"cve-2016-1000352-in-bouncy-castle-jce-provider-the-ecies-implementation-allowed","title":"In Bouncy Castle JCE Provider the ECIES implementation allowed the use of ECB mode","severity":"low","exploited":false,"published_at":"2018-10-17T16:27:38+00:00","url":"https://junglewise.ai/threats/cve-2016-1000352-in-bouncy-castle-jce-provider-the-ecies-implementation-allowed"},{"cve":"CVE-2016-1000346","cvss":3,"epss":0.023,"slug":"cve-2016-1000346-in-bouncy-castle-jce-provider-the-other-party-dh-public-key-is","title":"In Bouncy Castle JCE Provider the other party DH public key is not fully validated","severity":"low","exploited":false,"published_at":"2018-10-17T16:27:28+00:00","url":"https://junglewise.ai/threats/cve-2016-1000346-in-bouncy-castle-jce-provider-the-other-party-dh-public-key-is"},{"cve":"CVE-2016-1000343","cvss":3,"epss":0.032,"slug":"cve-2016-1000343-in-bouncy-castle-jce-provider-the-dsa-key-pair-generator","title":"In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default values","severity":"low","exploited":false,"published_at":"2018-10-17T16:24:22+00:00","url":"https://junglewise.ai/threats/cve-2016-1000343-in-bouncy-castle-jce-provider-the-dsa-key-pair-generator"},{"cve":"CVE-2016-1000342","cvss":3,"epss":0.018,"slug":"cve-2016-1000342-in-bouncy-castle-jce-provider-ecdsa-does-not-fully-validate-asn","title":"In Bouncy Castle JCE Provider ECDSA does not fully validate ASN.1 encoding of signature on verification","severity":"low","exploited":false,"published_at":"2018-10-17T16:24:12+00:00","url":"https://junglewise.ai/threats/cve-2016-1000342-in-bouncy-castle-jce-provider-ecdsa-does-not-fully-validate-asn"},{"cve":"CVE-2016-1000341","cvss":3,"epss":0.0261,"slug":"cve-2016-1000341-moderate-severity-vulnerability-that-affects-org-bouncycastle","title":"Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15","severity":"low","exploited":false,"published_at":"2018-10-17T16:24:00+00:00","url":"https://junglewise.ai/threats/cve-2016-1000341-moderate-severity-vulnerability-that-affects-org-bouncycastle"},{"cve":"CVE-2016-1000340","cvss":3,"epss":0.0226,"slug":"cve-2016-1000340-the-bouncy-castle-jce-provider-carry-a-propagation-bug","title":"The Bouncy Castle JCE Provider carry a propagation bug","severity":"low","exploited":false,"published_at":"2018-10-17T16:23:50+00:00","url":"https://junglewise.ai/threats/cve-2016-1000340-the-bouncy-castle-jce-provider-carry-a-propagation-bug"},{"cve":"CVE-2016-1000339","cvss":3,"epss":0.027,"slug":"cve-2016-1000339-moderate-severity-vulnerability-that-affects-org-bouncycastle","title":"Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15","severity":"low","exploited":false,"published_at":"2018-10-17T16:23:38+00:00","url":"https://junglewise.ai/threats/cve-2016-1000339-moderate-severity-vulnerability-that-affects-org-bouncycastle"},{"cve":"CVE-2016-1000338","cvss":3.1,"epss":0.0186,"slug":"cve-2016-1000338-in-bouncy-castle-jce-provider-it-is-possible-to-inject-extra","title":"In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validate","severity":"low","exploited":false,"published_at":"2018-10-17T16:23:26+00:00","url":"https://junglewise.ai/threats/cve-2016-1000338-in-bouncy-castle-jce-provider-it-is-possible-to-inject-extra"},{"cve":"CVE-2018-1000613","cvss":3,"epss":0.0477,"slug":"cve-2018-1000613-deserialization-of-untrusted-data-in-bouncy-castle","title":"Deserialization of Untrusted Data in Bouncy castle","severity":"low","exploited":false,"published_at":"2018-10-17T16:23:12+00:00","url":"https://junglewise.ai/threats/cve-2018-1000613-deserialization-of-untrusted-data-in-bouncy-castle"},{"cve":"CVE-2018-1000180","cvss":3,"epss":0.0358,"slug":"cve-2018-1000180-bouncy-castle-has-a-flaw-in-the-low-level-interface-to-rsa-key","title":"Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator","severity":"low","exploited":false,"published_at":"2018-10-16T17:44:39+00:00","url":"https://junglewise.ai/threats/cve-2018-1000180-bouncy-castle-has-a-flaw-in-the-low-level-interface-to-rsa-key"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"com.liferay.portal:release.portal.bom (Maven)","slug":"com-liferay-portal-release-portal-bom","vulnerabilities":92,"url":"https://junglewise.ai/threats/technologies/com-liferay-portal-release-portal-bom"},{"name":"org.keycloak:keycloak-services (Maven)","slug":"org-keycloak-keycloak-services","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-services"},{"name":"org.keycloak:keycloak-core (Maven)","slug":"org-keycloak-keycloak-core","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-core"},{"name":"org.apache.struts:struts2-core (Maven)","slug":"org-apache-struts-struts2-core","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/org-apache-struts-struts2-core"},{"name":"net.mingsoft:ms-mcms (Maven)","slug":"net-mingsoft-ms-mcms","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/net-mingsoft-ms-mcms"},{"name":"com.thoughtworks.xstream:xstream (Maven)","slug":"com-thoughtworks-xstream-xstream","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/com-thoughtworks-xstream-xstream"},{"name":"com.jfinal:jfinal (Maven)","slug":"com-jfinal-jfinal","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/com-jfinal-jfinal"},{"name":"org.jenkins-ci.plugins:script-security (Maven)","slug":"org-jenkins-ci-plugins-script-security","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/org-jenkins-ci-plugins-script-security"},{"name":"org.apache.tomcat:tomcat (Maven)","slug":"org-apache-tomcat-tomcat","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/org-apache-tomcat-tomcat"},{"name":"com.liferay.portal:release.dxp.bom (Maven)","slug":"com-liferay-portal-release-dxp-bom","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/com-liferay-portal-release-dxp-bom"},{"name":"org.opencms:opencms-core (Maven)","slug":"org-opencms-opencms-core","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/org-opencms-opencms-core"},{"name":"org.keycloak:keycloak-parent (Maven)","slug":"org-keycloak-keycloak-parent","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-parent"}],"technology":{"hub":true,"name":"org.bouncycastle:bcprov-jdk15on (Maven)","slug":"org-bouncycastle-bcprov-jdk15on","vendor":{"name":"Maven","slug":"maven","url":"https://junglewise.ai/threats/vendors/maven"},"aliases":[],"homepage":"https://www.bouncycastle.org/java.html","repo_url":"https://github.com/bcgit/bc-java","description":"A Java library providing cryptographic APIs for JDK 1.5 and later.","url":"https://junglewise.ai/threats/technologies/org-bouncycastle-bcprov-jdk15on"},"most_severe":[{"cve":"CVE-2024-34447","cvss":5.9,"epss":0.0077,"slug":"cve-2024-34447-bouncy-castle-java-cryptography-api-dns-poisoning-in-bcjsse","title":"Bouncy Castle Java Cryptography API DNS poisoning in BCJSSE","severity":"medium","exploited":false,"published_at":"2024-05-03T18:30:37+00:00","url":"https://junglewise.ai/threats/cve-2024-34447-bouncy-castle-java-cryptography-api-dns-poisoning-in-bcjsse"},{"cve":"CVE-2020-28052","cvss":3.1,"epss":0.0723,"slug":"cve-2020-28052-logic-error-in-legion-of-the-bouncy-castle-bc-java","title":"Logic error in Legion of the Bouncy Castle BC Java","severity":"low","exploited":false,"published_at":"2021-04-30T16:14:15+00:00","url":"https://junglewise.ai/threats/cve-2020-28052-logic-error-in-legion-of-the-bouncy-castle-bc-java"},{"cve":"CVE-2016-1000338","cvss":3.1,"epss":0.0186,"slug":"cve-2016-1000338-in-bouncy-castle-jce-provider-it-is-possible-to-inject-extra","title":"In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validate","severity":"low","exploited":false,"published_at":"2018-10-17T16:23:26+00:00","url":"https://junglewise.ai/threats/cve-2016-1000338-in-bouncy-castle-jce-provider-it-is-possible-to-inject-extra"},{"cve":"CVE-2020-15522","cvss":3.1,"epss":0.0152,"slug":"cve-2020-15522-timing-based-private-key-exposure-in-bouncy-castle","title":"Timing based private key exposure in Bouncy Castle","severity":"low","exploited":false,"published_at":"2021-08-13T15:22:31+00:00","url":"https://junglewise.ai/threats/cve-2020-15522-timing-based-private-key-exposure-in-bouncy-castle"},{"cve":"CVE-2024-29857","cvss":3.1,"epss":0.011,"slug":"cve-2024-29857-bouncy-castle-certificate-parsing-issues-cause-high-cpu-usage","title":"Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.","severity":"low","exploited":false,"published_at":"2024-05-14T15:32:54+00:00","url":"https://junglewise.ai/threats/cve-2024-29857-bouncy-castle-certificate-parsing-issues-cause-high-cpu-usage"},{"cve":"CVE-2023-33202","cvss":3.1,"epss":0.0102,"slug":"cve-2023-33202-bouncy-castle-denial-of-service-dos","title":"Bouncy Castle Denial of Service (DoS)","severity":"low","exploited":false,"published_at":"2023-11-23T18:30:33+00:00","url":"https://junglewise.ai/threats/cve-2023-33202-bouncy-castle-denial-of-service-dos"},{"cve":"CVE-2020-26939","cvss":3.1,"epss":0.0093,"slug":"cve-2020-26939-observable-differences-in-behavior-to-error-inputs-in-bouncy","title":"Observable Differences in Behavior to Error Inputs in Bouncy Castle","severity":"low","exploited":false,"published_at":"2021-04-22T16:16:49+00:00","url":"https://junglewise.ai/threats/cve-2020-26939-observable-differences-in-behavior-to-error-inputs-in-bouncy"},{"cve":"CVE-2024-30171","cvss":3.1,"epss":0.009,"slug":"cve-2024-30171-bouncy-castle-affected-by-timing-side-channel-for-rsa-key","title":"Bouncy Castle affected by timing side-channel for RSA key exchange (\"The Marvin Attack\")","severity":"low","exploited":false,"published_at":"2024-05-14T15:32:54+00:00","url":"https://junglewise.ai/threats/cve-2024-30171-bouncy-castle-affected-by-timing-side-channel-for-rsa-key"},{"cve":"CVE-2023-33201","cvss":3.1,"epss":0.0077,"slug":"cve-2023-33201-bouncy-castle-for-java-ldap-injection-vulnerability","title":"Bouncy Castle For Java LDAP injection vulnerability","severity":"low","exploited":false,"published_at":"2023-07-05T03:30:23+00:00","url":"https://junglewise.ai/threats/cve-2023-33201-bouncy-castle-for-java-ldap-injection-vulnerability"},{"cve":"CVE-2018-5382","cvss":3.1,"epss":0.0026,"slug":"cve-2018-5382-improper-validation-of-integrity-check-value-in-bouncy-castle","title":"Improper Validation of Integrity Check Value in Bouncy Castle","severity":"low","exploited":false,"published_at":"2022-05-13T01:01:01+00:00","url":"https://junglewise.ai/threats/cve-2018-5382-improper-validation-of-integrity-check-value-in-bouncy-castle"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}