https://seclists.org/oss-sec/2026/q3/402: Bouncy Castle 1.85 lease fixes 32 CVEs
Published Aug 4, 2026
·Updated
Affected Software
1 affected component
Bouncy Castle Bouncy Castle Java=1.85
The July 28 Bouncy Castle Java 1.85 release contains fixes for 32 CVEs. The provided information does not identify which earlier releases are affected or whether any affected functionality is enabled by default.
Prioritize environments that process untrusted certificate names, keystores, CMS AuthEnvelopedData, OpenPGP AEAD data, MLS wire data, PKCS#12 content, or RSA PKCS#1 signatures, as these are named in the reported issues. The available information does not provide a configuration-based method to determine exposure.