CVE-2024-29857
published 2024-05-14CVE-2024-29857: An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C#…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.10%
62.0th percentile
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bouncycastle | < bouncycastle 1.80-1 (forky) | bouncycastle 1.80-1 (forky) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bouncy Castle vulnerabilities
vendor_ubuntu·2026-03-18·CVSS 5.3
CVE-2025-8916 [MEDIUM] Bouncy Castle vulnerabilities
Title: Bouncy Castle vulnerabilities
Summary: Several security issues were fixed in Bouncy Castle.
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy
CISA ICS
Siemens SIDIS Prime
cisa_ics·2026-03-12·CVSS 7.5
[HIGH] Siemens SIDIS Prime
ICS Advisory
##
Siemens SIDIS Prime
Release DateMarch 12, 2026
Alert CodeICSA-26-071-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
SIDIS Prime before V4.0.800 is affected by multiple vulnerabilities in the components OpenSSL, SQLite, and several Node.js packages as described below. Siemens has released a new version of SIDIS Prime and recommends to update to the latest version.
The following versions of Siemens SIDIS Prime are affected:
- SIDIS Prime vers:intdot/<4.0.800 (CVE-2024-29857, CVE-2024-30171, CVE-2024-30172, CVE-2024-41996, CVE-2025-6965, CVE-2025-7783, CVE-2025-9230, CVE-2025-9232, CVE-2025-9670, CVE-2025-12816, CVE-2025-15284, CVE-2025-58751, CVE-2025-58752, CVE-2025-58754, CVE-202
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Adapters (Bouncy Castle Java Library) — CVE-2024-29857
vendor_oracle·2025-04-15·CVSS 7.5
CVE-2024-29857 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Adapters (Bouncy Castle Java Library) — CVE-2024-29857
Oracle Oracle Fusion Middleware Risk Matrix: Adapters (Bouncy Castle Java Library) vulnerability
CVE: CVE-2024-29857
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Agent Next Gen (Bouncy Castle Java Library) — CVE-2024-29857
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2024-29857 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Agent Next Gen (Bouncy Castle Java Library) — CVE-2024-29857
Oracle Oracle Enterprise Manager Risk Matrix: Agent Next Gen (Bouncy Castle Java Library) vulnerability
CVE: CVE-2024-29857
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Discovery Microservice (Bouncy Castle Java Library) — CVE-2024-29857
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2024-29857 [HIGH] Oracle Oracle Communications Risk Matrix: Discovery Microservice (Bouncy Castle Java Library) — CVE-2024-29857
Oracle Oracle Communications Risk Matrix: Discovery Microservice (Bouncy Castle Java Library) vulnerability
CVE: CVE-2024-29857
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: NextGen Installer (Bouncy Castle Java Library) — CVE-2024-29857
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2024-29857 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: NextGen Installer (Bouncy Castle Java Library) — CVE-2024-29857
Oracle Oracle Fusion Middleware Risk Matrix: NextGen Installer (Bouncy Castle Java Library) vulnerability
CVE: CVE-2024-29857
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Red Hat
org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service
vendor_redhat·2024-06-14·CVSS 7.5
CVE-2024-29857 [HIGH] CWE-20 org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service
org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
A vulnerability was found in Bouncy Castle. An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java). Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
Package: org.bouncycastle:bcprov-jdk18on (Cryostat 2) - Not affected
Package: org.bouncycastle:bcpr
Debian
CVE-2024-29857: bouncycastle - An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC...
vendor_debian·2024·CVSS 7.5
CVE-2024-29857 [HIGH] CVE-2024-29857: bouncycastle - An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC...
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.80-1)
sid: resolved (fixed in 1.80-1)
trixie: resolved (fixed in 1.80-1)
OSV
bouncycastle vulnerabilities
osv·2026-03-18·CVSS 5.3
CVE-2023-33201 [MEDIUM] bouncycastle vulnerabilities
bouncycastle vulnerabilities
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy Castle leaked timing information when
handling exceptions during an RSA
OSV
CVE-2024-29857: An issue was discovered in ECCurve
osv·2024-05-14·CVSS 7.5
CVE-2024-29857 [HIGH] CVE-2024-29857: An issue was discovered in ECCurve
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
OSV
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
osv·2024-05-14
CVE-2024-29857 [MEDIUM] Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
GHSA
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
ghsa·2024-05-14
CVE-2024-29857 [MEDIUM] CWE-125 Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
No detection rules found.
No public exploits indexed.
https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857https://www.bouncycastle.org/latest_releases.htmlhttps://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857https://security.netapp.com/advisory/ntap-20241206-0008/https://www.bouncycastle.org/latest_releases.html
2024-05-14
Published