BouncyCastle.Cryptography
BouncyCastle.NET is a popular cryptography library for .NET
Activity
- Latest release
- 1y ago
- Total releases
- 14
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Nov 15, 2022
| Version | Released | |
|---|---|---|
2.7.0-beta.98
pre
|
2.7.0-beta.98
pre
|
|
2.6.2
patch
|
2.6.2
patch
|
|
2.6.1
patch
|
2.6.1
patch
|
|
2.6.0
minor
|
2.6.0
minor
|
|
2.5.1
patch
|
2.5.1
patch
|
|
2.5.0
minor
|
2.5.0
minor
|
|
2.4.0
minor
|
2.4.0
minor
|
|
2.3.1
patch
|
2.3.1
patch
|
|
2.3.0
minor
3 CVEs
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.3.0
minor
|
|
2.2.1
patch
3 CVEs
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.2.1
patch
|
|
2.2.0
minor
3 CVEs
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.2.0
minor
|
|
2.1.1
patch
3 CVEs
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.1.1
patch
|
|
2.1.0
minor
3 CVEs
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.1.0
minor
|
|
2.0.0
initial
3 CVEs
CVE-2024-29857
GHSA-8xfc-gm6g-vgpv
May 14, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30172
GHSA-m44j-cfrm-g8qc
May 14, 2024
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Medium
Network
Low
None
None
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-30171
GHSA-v435-xc8x-wvr9
May 14, 2024
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. Affected versions
2.0.0
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0
initial
|