l
legion of the bouncy castle
Security Risk Profile
44
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 4 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 24, 2025 to present
4
Total CVEs
3
Critical+High
0
Exploited
3
Unpatched
Threat Assessment
Avg CVSS
7.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
44/100
medium
📈 3 in Last 30 Days
Severity Distribution
Critical
0High
3Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
No CWE data available
Most Affected Products
1. Legion of the Bouncy Castle bc-csharp2
2. Legion of the Bouncy Castle Bouncy Castle C#1
3. Legion of the Bouncy Castle Bouncy Castle for Java FIPS1
4. Legion of the Bouncy Castle Bouncy Castle for Java LTS1
5. maven/org.bouncycastle:bcprov-debug-lts8on1
Recent Vulnerabilities
See more →CVE-2026-103603
CVSS 8.7high
Unbounded HSS public key level count allows huge array allocation during signature verification
Oct 2, 2026🔧 No Patch
CVE-2026-103600
CVSS 8.7high
Unbounded ASN.1 nesting depth causes process-terminating stack overflow
Oct 2, 2026🔧 No Patch
CVE-2026-63575
CVSS 7.1high
PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count
Oct 2, 2026🔧 No Patch
CVE-2025-12194
CVSS 5.9medium
Oct 24, 2025
Monitor legion of the bouncy castle in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.