CVE-2025-14813
published 2026-04-15CVE-2025-14813: : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.31%
23.7th percentile
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).
This vulnerability is associated with program files G3413CTRBlockCipher.
This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| candlepinproject | candlepin | — | — |
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| jenkins | jenkins | — | — |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.59 < 1.80.2 | 1.80.2 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.81 < 1.81.1 | 1.81.1 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.82 < 1.84 | 1.84 |
| ocp-tools-4 | jenkins-rhel8 | — | — |
| ocp-tools-4 | jenkins-rhel9 | — | — |
| pki-core_10.6 | resteasy | — | — |
| pki-deps_10.6 | resteasy | — | — |
| redhat | resteasy | — | — |
| rhoai | odh-modelmesh-rhel8 | — | — |
| rhoai | odh-modelmesh-rhel9 | — | — |
| satellite_el8 | candlepin | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.09.3CRITICALCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Red
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-574f-3g2m-x479: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc
ghsa_unreviewed·2026-04-17
CVE-2025-14813 [CRITICAL] CWE-327 GHSA-574f-3g2m-x479: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher.
GOSTCTR implementation unable to process more than 255 blocks correctly.
This issue affects BC-JAVA: from 1.59 before 1.84.
GHSA
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
ghsa·2026-04-17
CVE-2025-14813 [CRITICAL] CWE-323 Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).
VulDB
Legion of the Bouncy Castle BC-JAVA up to 1.83 risky encryption
vuldb·2026-04-15·CVSS 9.3
CVE-2025-14813 [CRITICAL] Legion of the Bouncy Castle BC-JAVA up to 1.83 risky encryption
A vulnerability was found in Legion of the Bouncy Castle BC-JAVA up to 1.83. It has been classified as problematic. This issue affects some unknown processing. This manipulation causes risky cryptographic algorithm.
This vulnerability is handled as CVE-2025-14813. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is recommended.
Red Hat
bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
vendor_redhat·2026-04-15·CVSS 9.3
CVE-2025-14813 [CRITICAL] CWE-327 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
A flaw was found in Legion of the Bouncy Castle Inc. BC-JAVA bcprov. The `GOSTCTR` implementation is unable to securely process more than 255 blocks of data due to keystream reuse. This issue allows an attacker to break the fundamental confidentiality of any data protected by the `G3413CTRBlockCipher`, potentially leading to the recovery and access of encrypted data.
Statement: To exploit this flaw, an attacker needs to capture ciphertext encrypted by the `GOSTCTR` implementation where the `G3413CTRBlockCipher` processed more than 255 blocks of data, resulting in keystream reuse. An attack typically requires capturing these overlapping ciphertexts to perform cryptanalysis and uncover the underl
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-14813 canl-java: GOSTCTR implementation unable to process more than 255 blocks correctly [epel-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 canl-java: GOSTCTR implementation unable to process more than 255 blocks correctly [epel-all]
CVE-2025-14813 canl-java: GOSTCTR implementation unable to process more than 255 blocks correctly [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 pdfbox: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 pdfbox: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
CVE-2025-14813 pdfbox: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 canl-java: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 canl-java: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
CVE-2025-14813 canl-java: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 pdftk-java: GOSTCTR implementation unable to process more than 255 blocks correctly [epel-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 pdftk-java: GOSTCTR implementation unable to process more than 255 blocks correctly [epel-all]
CVE-2025-14813 pdftk-java: GOSTCTR implementation unable to process more than 255 blocks correctly [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 jglobus: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 jglobus: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
CVE-2025-14813 jglobus: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 resteasy: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 resteasy: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
CVE-2025-14813 resteasy: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 pdftk-java: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 pdftk-java: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
CVE-2025-14813 pdftk-java: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 voms-api-java: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 voms-api-java: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
CVE-2025-14813 voms-api-java: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 byte-buddy: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 byte-buddy: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
CVE-2025-14813 byte-buddy: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 apache-commons-vfs: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 apache-commons-vfs: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
CVE-2025-14813 apache-commons-vfs: GOSTCTR implementation unable to process more than 255 blocks correctly [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 voms-api-java: GOSTCTR implementation unable to process more than 255 blocks correctly [epel-all]
bugzilla·2026-04-28·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 voms-api-java: GOSTCTR implementation unable to process more than 255 blocks correctly [epel-all]
CVE-2025-14813 voms-api-java: GOSTCTR implementation unable to process more than 255 blocks correctly [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-14813 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
bugzilla·2026-04-15·CVSS 9.3
CVE-2025-14813 [CRITICAL] CVE-2025-14813 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
CVE-2025-14813 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher.
GOSTCTR implementation unable to process more than 255 blocks correctly.
This issue affects BC-JAVA: from 1.59 before 1.84.
https://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871fhttps://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813https://access.redhat.com/errata/RHSA-2026:11720https://access.redhat.com/errata/RHSA-2026:11721https://access.redhat.com/errata/RHSA-2026:13631https://access.redhat.com/errata/RHSA-2026:14272https://access.redhat.com/errata/RHSA-2026:14276https://access.redhat.com/errata/RHSA-2026:17668https://access.redhat.com/errata/RHSA-2026:18054https://access.redhat.com/errata/RHSA-2026:18055https://access.redhat.com/errata/RHSA-2026:18059https://access.redhat.com/errata/RHSA-2026:21772https://access.redhat.com/errata/RHSA-2026:24977https://access.redhat.com/errata/RHSA-2026:53644https://access.redhat.com/errata/RHSA-2026:53806https://access.redhat.com/errata/RHSA-2026:60239https://access.redhat.com/errata/RHSA-2026:60246https://access.redhat.com/errata/RHSA-2026:60247https://access.redhat.com/errata/RHSA-2026:60248https://access.redhat.com/errata/RHSA-2026:60249https://access.redhat.com/errata/RHSA-2026:60250https://access.redhat.com/errata/RHSA-2026:60251https://access.redhat.com/errata/RHSA-2026:60252https://access.redhat.com/errata/RHSA-2026:60254https://access.redhat.com/errata/RHSA-2026:60256https://access.redhat.com/errata/RHSA-2026:60259https://access.redhat.com/security/cve/CVE-2025-14813https://bugzilla.redhat.com/show_bug.cgi?id=2458640https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json
2026-04-15
Published