CVE-2026-58063
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Amber
Summary
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 0 < 1.85 | affected |
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 < 2.73.12 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.0 < 1.0.2.7 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 2.0.0 < 2.0.2 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 2.1.0 < 2.1.3 | affected |
Weaknesses
- CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058063
- https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.