{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/bouncy-castle-for-java--1.78/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bouncy_castle:for_java:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-29857"},{"cvss":5.9,"id":"CVE-2024-30171"},{"cvss":7.5,"id":"CVE-2024-30172"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bouncy Castle for Java (\u003c 1.78)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","java","cryptography"],"_cs_type":"advisory","_cs_vendors":["Bouncy Castle"],"content_html":"\u003cp\u003eBouncy Castle for Java is affected by several critical vulnerabilities, identified as CVE-2024-29857, CVE-2024-30171, and CVE-2024-30172. These security flaws allow a remote, unauthenticated attacker to manipulate cryptographic operations, bypass security controls, and disclose sensitive information or cause a denial-of-service (DoS) state. Because Bouncy Castle is a widely deployed cryptographic library used by numerous enterprise Java applications, these vulnerabilities represent a significant risk for systems relying on its underlying providers for TLS, data signing, and object serialization. Defenders must assess their application inventory to identify dependencies on the vulnerable versions and coordinate updates with application development teams.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in the total compromise of cryptographic integrity within the affected Java applications. This potentially leads to the interception of encrypted communications, unauthorized access to secure data, or the complete disruption of services dependent on these cryptographic primitives.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all Java-based applications within the enterprise environment that bundle or depend on Bouncy Castle libraries.\u003c/li\u003e\n\u003cli\u003eReview the official Bouncy Castle project release notes to identify the patched library versions for CVE-2024-29857, CVE-2024-30171, and CVE-2024-30172.\u003c/li\u003e\n\u003cli\u003eUpdate all identified vulnerable application components to the latest patched releases of Bouncy Castle.\u003c/li\u003e\n\u003cli\u003ePerform dependency scans using Software Bill of Materials (SBOM) or SCA tooling to ensure no transitive dependencies include the vulnerable Bouncy Castle binaries.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T18:42:28Z","date_published":"2026-10-05T18:42:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-bouncy-castle-vulnerabilities/","summary":"Bouncy Castle for Java is affected by multiple vulnerabilities that allow remote attackers to perform privilege escalation, security bypass, data manipulation, information disclosure, or denial-of-service.","title":"Multiple Vulnerabilities in Bouncy Castle for Java","url":"https://feed.craftedsignal.io/briefs/2026-10-bouncy-castle-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Bouncy Castle for Java (\u003c 1.78)","version":"https://jsonfeed.org/version/1.1"}