oss-sec mailing list archives

Re: Bouncy Castle 1.85 release fixes 32 CVEs


From: TvT <tvtreeck () nepatec de>
Date: Wed, 5 Aug 2026 17:39:21 +1200

I had the same thought so I asked the project owner and he shared the story
:-)

https://github.com/bcgit/bc-java/discussions/2388


Am Mi., 5. Aug. 2026 um 05:24 Uhr schrieb Alan Coopersmith <
alan.coopersmith () oracle com>:

On 8/3/2026 7:37 PM, Peter Gutmann wrote:
Alan Coopersmith <alan.coopersmith () oracle com> writes:

It also says the release contains fixes for the following CVEs:

Given the quantity and sweeping scope of those, was this the result of
some
new tool used for code analysis?  I'm assuming AI, it sounds like
there'd be
an interesting backstory to how all of this was turned up.
I didn't see anything in the announcements from the Bouncy Castle folks
about that.

They do have more info about the CVE's in their wiki, such as:
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763
but I don't see any reference there to how they were found/reported.

Current thread: