Description
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Severity (CVSS)
| Base score | 5.3 |
|---|---|
| Severity | Medium |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Amber |
| Provided by | CNA |
Weaknesses
- CWE-770 — CWE-770 Allocation of Resources Without Limits or Throttling
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 0 to <1.85 |
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 to <2.73.12 |
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.0 to <1.0.2.7; 2.0.0 to <2.0.2; 2.1.0 to <2.1.3 |
References
Generated from the official CVE List on 03 Aug 2026 08:53 UTC.