Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <CAFhtw61Gdx8q-Ls0cjaYyNiQG5z85N+mYMXw8QMNOvAw=HNkGw@mail.gmail.com>
Date: Wed, 5 Aug 2026 17:39:21 +1200
From: TvT <tvtreeck@...atec.de>
To: oss-security@...ts.openwall.com
Cc: Peter Gutmann <pgut001@...auckland.ac.nz>
Subject: Re: Bouncy Castle 1.85 release fixes 32 CVEs

I had the same thought so I asked the project owner and he shared the story
:-)

https://github.com/bcgit/bc-java/discussions/2388


Am Mi., 5. Aug. 2026 um 05:24 Uhr schrieb Alan Coopersmith <
alan.coopersmith@...cle.com>:

> On 8/3/2026 7:37 PM, Peter Gutmann wrote:
> > Alan Coopersmith <alan.coopersmith@...cle.com> writes:
> >
> >> It also says the release contains fixes for the following CVEs:
> >
> > Given the quantity and sweeping scope of those, was this the result of
> some
> > new tool used for code analysis?  I'm assuming AI, it sounds like
> there'd be
> > an interesting backstory to how all of this was turned up.
> I didn't see anything in the announcements from the Bouncy Castle folks
> about that.
>
> They do have more info about the CVE's in their wiki, such as:
> https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763
> but I don't see any reference there to how they were found/reported.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.