CVE-2024-30172
published 2024-05-14CVE-2024-30172: An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.75%
50.9th percentile
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | bitbucket_data_center | — | — |
| debian | bouncycastle | < bouncycastle 1.80-1 (forky) | bouncycastle 1.80-1 (forky) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bouncy Castle vulnerabilities
vendor_ubuntu·2026-03-18·CVSS 5.3
CVE-2025-8916 [MEDIUM] Bouncy Castle vulnerabilities
Title: Bouncy Castle vulnerabilities
Summary: Several security issues were fixed in Bouncy Castle.
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy
CISA ICS
Siemens SIDIS Prime
cisa_ics·2026-03-12·CVSS 7.5
[HIGH] Siemens SIDIS Prime
ICS Advisory
##
Siemens SIDIS Prime
Release DateMarch 12, 2026
Alert CodeICSA-26-071-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
SIDIS Prime before V4.0.800 is affected by multiple vulnerabilities in the components OpenSSL, SQLite, and several Node.js packages as described below. Siemens has released a new version of SIDIS Prime and recommends to update to the latest version.
The following versions of Siemens SIDIS Prime are affected:
- SIDIS Prime vers:intdot/<4.0.800 (CVE-2024-29857, CVE-2024-30171, CVE-2024-30172, CVE-2024-41996, CVE-2025-6965, CVE-2025-7783, CVE-2025-9230, CVE-2025-9232, CVE-2025-9670, CVE-2025-12816, CVE-2025-15284, CVE-2025-58751, CVE-2025-58752, CVE-2025-58754, CVE-202
Oracle
Oracle Oracle Analytics Risk Matrix: Platform Security (Bouncy Castle Java Library) — CVE-2024-30172
vendor_oracle·2025-04-15·CVSS 7.5
CVE-2024-30172 [HIGH] Oracle Oracle Analytics Risk Matrix: Platform Security (Bouncy Castle Java Library) — CVE-2024-30172
Oracle Oracle Analytics Risk Matrix: Platform Security (Bouncy Castle Java Library) vulnerability
CVE: CVE-2024-30172
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Atlassian
CVE-2024-30172: 8.19.0 to 8.19.2 (LTS) 8.18.0 to 8.18.1 8.17.0 to 8.17.2 8.16.0 to 8.16.4 8.15.0 to 8.15.5 8.14.0 to 8.14.6 8.13.0 to 8.
vendor_atlassian·2024-11-19·CVSS 8.2
CVE-2024-30172 [HIGH] CVE-2024-30172: 8.19.0 to 8.19.2 (LTS) 8.18.0 to 8.18.1 8.17.0 to 8.17.2 8.16.0 to 8.16.4 8.15.0 to 8.15.5 8.14.0 to 8.14.6 8.13.0 to 8.
CVE-2024-30172: 8.19.0 to 8.19.2 (LTS) 8.18.0 to 8.18.1 8.17.0 to 8.17.2 8.16.0 to 8.16.4 8.15.0 to 8.15.5 8.14.0 to 8.14.6 8.13.0 to 8.
8.19.0 to 8.19.2 (LTS) 8.18.0 to 8.18.1 8.17.0 to 8.17.2 8.16.0 to 8.16.4 8.15.0 to 8.15.5 8.14.0 to 8.14.6 8.13.0 to 8.13.6 8.12.0 to 8.12.6 8.11.0 to 8.11.6 8.10.0 to 8.10.6 8.9.0 to 8.9.13 (LTS) 8.8.0 to 8.8.7 8.7.0 to 8.7.5 8.6.2 to 8.6.4 8.5.2 to 8.5.4 8.4.3 to 8.4.4 8.3.4
CVE: CVE-2024-30172
Affected products: Bitbucket Data Center
Red Hat
org.bouncycastle:bcprov-jdk18on: Infinite loop in ED25519 verification in the ScalarUtil class
vendor_redhat·2024-05-09·CVSS 7.5
CVE-2024-30172 [HIGH] CWE-835 org.bouncycastle:bcprov-jdk18on: Infinite loop in ED25519 verification in the ScalarUtil class
org.bouncycastle:bcprov-jdk18on: Infinite loop in ED25519 verification in the ScalarUtil class
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
A flaw was found in the Bouncy Castle Java Cryptography APIs. Affected versions of this package are vulnerable to an Infinite loop issue in ED25519 verification in the ScalarUtil class. This flaw allows an attacker to send a malicious signature and public key to trigger a denial of service.
Package: org.bouncycastle:bcprov-jdk18on (Cryostat 2) - Will not fix
Package: org.bouncycastle:bcprov-jdk18on (Cryostat 3) - Not affected
Package: org.bouncycastle:bcprov-jdk18on (Red Hat build of Apache Camel for Spring Boot 3) - Not aff
Debian
CVE-2024-30172: bouncycastle - An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An ...
vendor_debian·2024·CVSS 7.5
CVE-2024-30172 [HIGH] CVE-2024-30172: bouncycastle - An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An ...
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.80-1)
sid: resolved (fixed in 1.80-1)
trixie: resolved (fixed in 1.80-1)
OSV
CVE-2024-30172: An issue was discovered in Bouncy Castle Java Cryptography APIs before 1
osv·2024-05-14·CVSS 7.5
CVE-2024-30172 [HIGH] CVE-2024-30172: An issue was discovered in Bouncy Castle Java Cryptography APIs before 1
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
GHSA
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
ghsa·2024-05-14
CVE-2024-30172 [MEDIUM] CWE-835 Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
OSV
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
osv·2024-05-14
CVE-2024-30172 [MEDIUM] Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
An issue was discovered in Bouncy Castle Java Cryptography APIs starting in 1.73 and before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
No detection rules found.
No public exploits indexed.
2024-05-14
Published