https://seclists.org/oss-sec/2026/q3/407: Bouncy Castle 1.85 lease fixes 32 CVEs
Published Aug 4, 2026
·Updated
Affected Software
1 affected component
Bouncy Castle Bouncy Castle=1.85
Frequently Asked Questions
1
Can this information be used to determine whether a specific deployment is affected?
No. The provided material does not identify affected configurations, exposure conditions, or indicators that would show whether a deployment is affected.
2
Are any mitigations documented for organizations that cannot patch immediately?
No. The provided material does not describe temporary mitigations or workarounds for environments that cannot immediately move to the release containing the fixes.
3
Is the discovery or reporting method for these CVEs documented?
No. The discussion notes that neither the announcements nor the referenced CVE wiki information explains how the issues were found or reported.