The Bouncy Castle Java APIs for the TLS, including a JSSE provider. The APIs are designed primarily to be used in conjunction with the BC FIPS provider. The APIs may also be used with other providers although if being used in a FIPS context it is the responsibility of the user to ensure that any other providers used are FIPS certified and used appropriately.
97%
Total Score
95
100
96
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-486120 New bctls-fips is vulnerable to Denial of Service (DoS) in versions 1.0.0 - 1.0.23, 2.0.0 - 2.0.23 and 2.1.0 - 2.1.23. | 1.0.0 - 1.0.232.0.0 - 2.0.232.1.0 - 2.1.23 | Medium |
AIKIDO-2026-733725 New bctls-fips is vulnerable to Improper Certificate Validation in versions 1.0.7 - 1.0.23, 2.0.0 - 2.0.23 and 2.1.0 - 2.1.23. | 1.0.7 - 1.0.232.0.0 - 2.0.232.1.0 - 2.1.23 | High |
CVE-2024-30171 org.bouncycastle:bctls-fips is vulnerable to Observable Discrepancy in versions 0.0.0 - 1.0.19. | 0.0.0 - 1.0.19 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.bouncycastle:bcutil-fips Version [2.1.7,2.2.0) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant