GHSA-4vhj-98r6-424h · Severity: high · Ecosystem: maven — In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validate
In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.
Conclusion & alert: CVE-2016-1000338 is rated Moderate Risk (58.1/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.85%). Core evidence: EPSS rose +1.47% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.37% | 1.85% | +1.47% |
| 2 | 2026-03-13 | 0.29% | 0.37% | +0.08% |
| 3 | 2026-02-23 | — | 0.29% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-4vhj-98r6-424h · Severity: high · Ecosystem: maven — In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validate
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2016-1000338 not yet assigned priority: Debian including 1 source packages (bouncycastle), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2016-1000338 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2016-1000338 |
suse
|
high | CVE-2016-1000338 severity important: SUSE including 32 source package names (bouncycastle, bouncycastle-1.64-1.63, …), 34 product×package rows across 8 product lines (SUSE Linux Enterprise Module for Development Tools 15 SP2, SUSE Linux Enterprise Module for Development Tools 15 SP3, … (8 product lines)): Fixed 32, Known Not Affected 2. | https://www.suse.com/security/cve/CVE-2016-1000338/ |
ubuntu
|
medium | CVE-2016-1000338 medium priority: Ubuntu including 1 source packages (bouncycastle), 20 status rows across 20 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 17, released 2, needed 1. | https://ubuntu.com/security/CVE-2016-1000338 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| bouncycastle | legion-of-the-bouncy-castle-java-crytography-api | >= 1.38, < 1.56 | cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:*:*:*:*:*:*:*:* |
| redhat | satellite | 6.4 | cpe:2.3:a:redhat:satellite:6.4:-:*:*:*:*:*:* |
| redhat | satellite_capsule | 6.4 | cpe:2.3:a:redhat:satellite_capsule:6.4:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 14.04 | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:*:*:*:* |
| netapp | 7-mode_transition_tool | — | cpe:2.3:a:netapp:7-mode_transition_tool:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2018:2669 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2018:2927 | Third Party Advisory |
| https://github.com/bcgit/bc-java/commit/b0c3ce99d43d73a096268831d0d120ffc89eac7f#diff-3679f5a9d2b939d0d3ee1601a7774fb0 | Patch Third Party Advisory |
| https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2018/07/msg00009.html | Mailing List Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20231006-0011/ | Third Party Advisory |
| https://usn.ubuntu.com/3727-1/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuoct2020.html | Third Party Advisory |