Search/CVE-2015-7940
CVE

CVE-2015-7940

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."

CVSS v3.1
EPSS
4.82%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
8 relationships
Timeline
disclosure → media coverage
Nov 9, 2015
Disclosure — published as a CVE record. · last revised by NVD May 6, 2026