BouncyCastle
The Bouncy Castle Crypto package is a C# implementation of cryptographic algorithms and protocols, it was developed by the Legion of the Bouncy Castle, a registered Australian Charity, with a little help! The Legion, and the latest goings on with this package, can be found at [http://www.bouncycastle.org](http://www.bouncycastle.org). In addition to providing basic cryptography algorithms, the package also provides support for CMS, TSP, X.509 certificate generation and a variety of other standards such as OpenPGP.
Activity
- Latest release
- 5y ago
- Total releases
- 8
- Cadence
- ~9 months
- Last 12 months
- 0
Details
- First release
- Apr 30, 2011
| Version | Released | |
|---|---|---|
1.8.9
patch
3 CVEs
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.8.9
patch
|
|
1.8.6.1
patch
4 CVEs
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-15522
GHSA-6xx3-rg99-gc3p
Aug 13, 2021
Timing based private key exposure in Bouncy Castle
5.1
/ 10
Medium
Local
High
None
None
Unchanged
High
None
None
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
Fixed in
1.8.7
References Updated Sep 10, 2026 · Source: OSV.dev |
1.8.6.1
patch
|
|
1.8.5
patch
4 CVEs
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-15522
GHSA-6xx3-rg99-gc3p
Aug 13, 2021
Timing based private key exposure in Bouncy Castle
5.1
/ 10
Medium
Local
High
None
None
Unchanged
High
None
None
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
Fixed in
1.8.7
References Updated Sep 10, 2026 · Source: OSV.dev |
1.8.5
patch
|
|
1.8.4
patch
4 CVEs
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-15522
GHSA-6xx3-rg99-gc3p
Aug 13, 2021
Timing based private key exposure in Bouncy Castle
5.1
/ 10
Medium
Local
High
None
None
Unchanged
High
None
None
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
Fixed in
1.8.7
References Updated Sep 10, 2026 · Source: OSV.dev |
1.8.4
patch
|
|
1.8.3.1
patch
4 CVEs
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-15522
GHSA-6xx3-rg99-gc3p
Aug 13, 2021
Timing based private key exposure in Bouncy Castle
5.1
/ 10
Medium
Local
High
None
None
Unchanged
High
None
None
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
Fixed in
1.8.7
References Updated Sep 10, 2026 · Source: OSV.dev |
1.8.3.1
patch
|
|
1.8.2
patch
4 CVEs
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-15522
GHSA-6xx3-rg99-gc3p
Aug 13, 2021
Timing based private key exposure in Bouncy Castle
5.1
/ 10
Medium
Local
High
None
None
Unchanged
High
None
None
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
Fixed in
1.8.7
References Updated Sep 10, 2026 · Source: OSV.dev |
1.8.2
patch
|
|
1.8.1
minor
4 CVEs
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-15522
GHSA-6xx3-rg99-gc3p
Aug 13, 2021
Timing based private key exposure in Bouncy Castle
5.1
/ 10
Medium
Local
High
None
None
Unchanged
High
None
None
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
Fixed in
1.8.7
References Updated Sep 10, 2026 · Source: OSV.dev |
1.8.1
minor
|
|
1.7.0
initial
4 CVEs
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
1.8.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-15522
GHSA-6xx3-rg99-gc3p
Aug 13, 2021
Timing based private key exposure in Bouncy Castle
5.1
/ 10
Medium
Local
High
None
None
Unchanged
High
None
None
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures. Affected versions
1.7.0
1.8.1
1.8.2
1.8.3
1.8.3.1
1.8.4
1.8.5
1.8.6
1.8.6.1
Fixed in
1.8.7
References Updated Sep 10, 2026 · Source: OSV.dev |
1.7.0
initial
|