oss-sec mailing list archives

Re: Bouncy Castle 1.85 release fixes 32 CVEs


From: Alan Coopersmith <alan.coopersmith () oracle com>
Date: Tue, 4 Aug 2026 10:23:23 -0700

On 8/3/2026 7:37 PM, Peter Gutmann wrote:
Alan Coopersmith <alan.coopersmith () oracle com> writes:

It also says the release contains fixes for the following CVEs:

Given the quantity and sweeping scope of those, was this the result of some
new tool used for code analysis?  I'm assuming AI, it sounds like there'd be
an interesting backstory to how all of this was turned up.
I didn't see anything in the announcements from the Bouncy Castle folks
about that.

They do have more info about the CVE's in their wiki, such as:
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763
but I don't see any reference there to how they were found/reported.

--
        -Alan Coopersmith-                 alan.coopersmith () oracle com
         Oracle Solaris Engineering - https://blogs.oracle.com/solaris


Current thread: