Vulnerability GHSA-c3fc-8qff-9hwx
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 months ago
April 17, 2026 at 06:31 PM UTC
Bouncy Castle has an LDAP injection
1.74.0 - 1.83.0
1.74.0 - 1.83.0
Summary
Bouncy Castle has an LDAP injection
Details
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.84.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
1 month ago
Bouncy Castle: Lazy ASN.1 sequence forcing resets nesting-depth guard
1.71.0 - 1.80.0 and 1.80.2 - 1.84.0 GHSA-qp49-qgx5-5m26
1.71.0 - 1.80.0 and 1.80.2 - 1.84.0 GHSA-qp49-qgx5-5m26
High Risk
1 month ago
Bouncy Castle: Lazy ASN.1 sequence forcing resets nesting-depth guard
1.71.0 - 1.80.0 and 1.80.2 - 1.84.0 GHSA-qp49-qgx5-5m26
1.71.0 - 1.80.0 and 1.80.2 - 1.84.0 GHSA-qp49-qgx5-5m26
Critical
1 month ago
Bouncy Castle: Name Constraints bypass via trailing dot in rfc822Name and URI
1.71.0 - 1.80.0 and 1.80.2 - 1.84.0 GHSA-9pwp-9qqc-pr26
1.71.0 - 1.80.0 and 1.80.2 - 1.84.0 GHSA-9pwp-9qqc-pr26
Critical
1 month ago
Bouncy Castle: Name Constraints bypass via trailing dot in rfc822Name and URI
1.71.0 - 1.80.0 and 1.80.2 - 1.84.0 GHSA-9pwp-9qqc-pr26
1.71.0 - 1.80.0 and 1.80.2 - 1.84.0 GHSA-9pwp-9qqc-pr26
High Risk
5 months ago
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
1.59.0 - 1.65.0 and 1.67.0 - 1.83.0 GHSA-574f-3g2m-x479
1.59.0 - 1.65.0 and 1.67.0 - 1.83.0 GHSA-574f-3g2m-x479
Impacted packages
Timeline
Published
5 months ago
April 17, 2026 at 06:31 PM UTC
Fixed (1.84)
Unknown
Unknown
Fixed (1.84)
Unknown
Unknown
Fixed (1.84)
Unknown
Unknown
Last Modified
18 days ago
September 10, 2026 at 03:51 AM UTC