I had the same thought so I asked the project owner and he shared the story :-)
https://github.com/bcgit/bc-java/discussions/2388 Am Mi., 5. Aug. 2026 um 05:24 Uhr schrieb Alan Coopersmith < [email protected]>: > On 8/3/2026 7:37 PM, Peter Gutmann wrote: > > Alan Coopersmith <[email protected]> writes: > > > >> It also says the release contains fixes for the following CVEs: > > > > Given the quantity and sweeping scope of those, was this the result of > some > > new tool used for code analysis? I'm assuming AI, it sounds like > there'd be > > an interesting backstory to how all of this was turned up. > I didn't see anything in the announcements from the Bouncy Castle folks > about that. > > They do have more info about the CVE's in their wiki, such as: > https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763 > but I don't see any reference there to how they were found/reported.
