The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains the JCA/JCE provider and low-level API for the BC Java version 1.85 for Java 1.8 and later.
94%
Total Score
93
100
88
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-805345 New bcprov-jdk18on is vulnerable to Timing Attacks in versions 1.73 - 1.77. | 1.73 - 1.77 | High |
AIKIDO-2026-10630 bcprov-jdk18on is vulnerable to Observable Timing Discrepancy in versions 1.71 - 1.80.1, 1.81 - 1.81 and 1.82 - 1.83. | 1.71 - 1.80.11.81 - 1.811.82 - 1.83 | High |
CVE-2024-29857 org.bouncycastle:bcprov-jdk18on is vulnerable to Out-of-bounds Read in versions 0.0.0 - 1.78. | 0.0.0 - 1.78 | Medium |
CVE-2024-34447 org.bouncycastle:bcprov-jdk18on is vulnerable to Improper Validation of Certificate with Host Mismatch in versions 1.61 - 1.78. | 1.61 - 1.78 | Medium |
CVE-2023-33202 org.bouncycastle:bcprov-jdk18on is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 1.73. | 0.0.0 - 1.73 | Medium |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant