https://seclists.org/oss-sec/2026/q3/437: Bouncy Castle 1.85 lease fixes 32 CVEs
Published Aug 5, 2026
·Updated
Affected Software
1 affected component
Bouncy Castle Bouncy Castle Java=1.85
The project owner reportedly shared the background in Bouncy Castle's GitHub discussion 2388. The mailing-list post does not describe the discovery method itself.
The Bouncy Castle project wiki provides additional information for individual CVEs; the post cites CVE-2026-8763 as an example. The mailing-list post does not include technical details for the full set.