Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in Bouncy Castle for Java

Bouncy Castle for Java is affected by multiple vulnerabilities that allow remote attackers to perform privilege escalation, security bypass, data manipulation, information disclosure, or denial-of-service.

CVE search metadata

CVE search record: CVE-2024-29857. Severity: high. CVSS: 7.5. EPSS: 1.10%. KEV: no. Product: Bouncy Castle for Java (< 1.78). Brief: Multiple Vulnerabilities in Bouncy Castle for Java. Brief link: https://feed.craftedsignal.io/briefs/2026-10-bouncy-castle-vulnerabilities/

CVE search record: CVE-2024-30171. Severity: medium. CVSS: 5.9. EPSS: 0.90%. KEV: no. Product: Bouncy Castle for Java (< 1.78). Brief: Multiple Vulnerabilities in Bouncy Castle for Java. Brief link: https://feed.craftedsignal.io/briefs/2026-10-bouncy-castle-vulnerabilities/

CVE search record: CVE-2024-30172. Severity: high. CVSS: 7.5. EPSS: 0.75%. KEV: no. Product: Bouncy Castle for Java (< 1.78). Brief: Multiple Vulnerabilities in Bouncy Castle for Java. Brief link: https://feed.craftedsignal.io/briefs/2026-10-bouncy-castle-vulnerabilities/

Bouncy Castle for Java is affected by several critical vulnerabilities, identified as CVE-2024-29857, CVE-2024-30171, and CVE-2024-30172. These security flaws allow a remote, unauthenticated attacker to manipulate cryptographic operations, bypass security controls, and disclose sensitive information or cause a denial-of-service (DoS) state. Because Bouncy Castle is a widely deployed cryptographic library used by numerous enterprise Java applications, these vulnerabilities represent a significant risk for systems relying on its underlying providers for TLS, data signing, and object serialization. Defenders must assess their application inventory to identify dependencies on the vulnerable versions and coordinate updates with application development teams.

Impact

Successful exploitation of these vulnerabilities could result in the total compromise of cryptographic integrity within the affected Java applications. This potentially leads to the interception of encrypted communications, unauthorized access to secure data, or the complete disruption of services dependent on these cryptographic primitives.

Recommendation

  • Identify all Java-based applications within the enterprise environment that bundle or depend on Bouncy Castle libraries.
  • Review the official Bouncy Castle project release notes to identify the patched library versions for CVE-2024-29857, CVE-2024-30171, and CVE-2024-30172.
  • Update all identified vulnerable application components to the latest patched releases of Bouncy Castle.
  • Perform dependency scans using Software Bill of Materials (SBOM) or SCA tooling to ensure no transitive dependencies include the vulnerable Bouncy Castle binaries.

Immediate actions

Inventory all Java applications for dependencies on Bouncy Castle library versions

Application Security 48h

Mitigations

Patch Bouncy Castle for Java to 1.78 or later

immediate IT Operations

CVE-2024-29857, CVE-2024-30171, CVE-2024-30172