All findings

CVE-2026-8763 + 28 more critical

Bouncy Castle records twenty-nine Claude-assisted CVEs

Bouncy Castle and CVE records directly credit Alex Gaynor working with Claude and Anthropic Research across twenty-nine 2026 Java security fixes.

Bug class
Cryptographic validation, protocol, parsing, memory, and authentication flaws
Affected codebase
Bouncy Castle Java, LTS, and FIPS libraries
Credited system
Claude / Anthropic Research
Disclosed
August 2, 2026
Attribution
Direct source attribution
Severity
critical
Source status: Bouncy Castle's CNA records and CVE pages credit Alex Gaynor in collaboration with Claude and Anthropic Research. The project publishes affected versions and fixes for the exact identifiers; the cluster severity reflects the highest upstream rating.

Summary

The Bouncy Castle public record adds a sustained twenty-nine-CVE Claude-assisted campaign. The issues span certificate and hostname validation, CMS and OpenPGP, TLS, ASN.1 handling, cryptographic state, parsing, and related security boundaries across the Java, LTS, and FIPS lines.

Attribution

This is direct primary-source attribution. Bouncy Castle acts as CNA for the records and names the researcher, Claude, and Anthropic Research. Bugflation counts the exact public identifiers rather than every security fix in the same release series.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.