The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains the JCA/JCE provider and low-level API for the BC Java version 1.85.1 for Java 1.4.
97%
Total Score
91
100
98
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-32154 New bcprov-jdk14 is vulnerable to Timing Attacks in versions 1.73 - 1.77. | 1.73 - 1.77 | High |
AIKIDO-2026-10629 bcprov-jdk14 is vulnerable to Observable Timing Discrepancy in versions 1.71 - 1.83. | 1.71 - 1.83 | High |
CVE-2026-0636 org.bouncycastle:bcprov-jdk14 is vulnerable to Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') in versions 1.74 - 1.84. | 1.74 - 1.84 | Medium |
CVE-2025-14813 org.bouncycastle:bcprov-jdk14 is vulnerable to Reusing a Nonce, Key Pair in Encryption in versions 1.59 - 1.80.1, 1.81.0 - 1.81.0 and 1.82 - 1.83. | 1.59 - 1.80.11.81.0 - 1.81.01.82 - 1.83 | Critical |
CVE-2025-8885 org.bouncycastle:bcprov-jdk14 is vulnerable to Allocation of Resources Without Limits or Throttling in versions 1.0 - 1.78. | 1.0 - 1.78 | Medium |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant