CVE-2025-8885
published 2025-08-12CVE-2025-8885: Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the…
PriorityP337medium6.3CVSS 4.0
AVNACLATPPRNUINVCNVINVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSPAUXRUVXREMUAmber
EPSS
0.54%
41.9th percentile
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdenti... https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java .
This issue affects BC Java: from 1.0 through 1.77; BC-FJA: from 1.0.0 through 1.0.2.5, from 2.0.0 through 2.0.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bouncycastle | < bouncycastle 1.80-1 (forky) | bouncycastle 1.80-1 (forky) |
| legion_of_the_bouncy_castle_inc | bc-fja | 1.0.0 – 1.0.2.5 | — |
| legion_of_the_bouncy_castle_inc | bc-fja | 2.0.0 – 2.0.1 | — |
| legion_of_the_bouncy_castle_inc | bc_java | 1.0 – 1.77 | — |
CVSS provenance
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:U/V:X/RE:M/U:Amber
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_oracle4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-8885: Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc
osv·2025-08-12·CVSS 6.3
CVE-2025-8885 [MEDIUM] CVE-2025-8885: Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdenti... https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java . This issue affects BC Java: from 1.0 through 1.77; BC-FJA: from 1.0.0 through 1.0.2.5, from 2.0.0 through 2.0.1.
GHSA
Bouncy Castle for Java on All (API modules) allows Excessive Allocation
ghsa·2025-08-12
CVE-2025-8885 [MEDIUM] CWE-770 Bouncy Castle for Java on All (API modules) allows Excessive Allocation
Bouncy Castle for Java on All (API modules) allows Excessive Allocation
A resource allocation vulnerability exists in Bouncy Castle for Java (by Legion of the Bouncy Castle Inc.) that affects all API modules. The vulnerability allows attackers to cause excessive memory allocation through unbounded resource consumption, potentially leading to denial of service. The issue is located in the ASN1ObjectIdentifier.java file in the core module.
This issue affects Bouncy Castle for Java: from BC 1.0 through 1.77, from BC-FJA 1.0.0 through 2.0.0.
OSV
Bouncy Castle for Java on All (API modules) allows Excessive Allocation
osv·2025-08-12
CVE-2025-8885 [MEDIUM] Bouncy Castle for Java on All (API modules) allows Excessive Allocation
Bouncy Castle for Java on All (API modules) allows Excessive Allocation
A resource allocation vulnerability exists in Bouncy Castle for Java (by Legion of the Bouncy Castle Inc.) that affects all API modules. The vulnerability allows attackers to cause excessive memory allocation through unbounded resource consumption, potentially leading to denial of service. The issue is located in the ASN1ObjectIdentifier.java file in the core module.
This issue affects Bouncy Castle for Java: from BC 1.0 through 1.77, from BC-FJA 1.0.0 through 2.0.0.
Oracle
Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Bouncy Castle Java FIPS) — CVE-2025-8885
vendor_oracle·2025-10-15·CVSS 4.3
CVE-2025-8885 [MEDIUM] Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Bouncy Castle Java FIPS) — CVE-2025-8885
Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Bouncy Castle Java FIPS) vulnerability
CVE: CVE-2025-8885
CVSS: 4.3
Protocol: HTTPS
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
bouncycastle: Bouncy Castle denial of service parsing ASN.1 Object Identifiers
vendor_redhat·2025-08-12·CVSS 6.3
CVE-2025-8885 [MEDIUM] CWE-770 bouncycastle: Bouncy Castle denial of service parsing ASN.1 Object Identifiers
bouncycastle: Bouncy Castle denial of service parsing ASN.1 Object Identifiers
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdenti... https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java .
This issue affects BC Java: from 1.0 through 1.77; BC-FJA: from 1.0.0 through 1.0.2.5, from 2.0.0 through 2.0.1.
A resource exhaustion flaw has been discovered in the Bouncy Castle for Java library. The flaw exists because ther
Debian
CVE-2025-8885: bouncycastle - Allocation of Resources Without Limits or Throttling vulnerability in Legion of ...
vendor_debian·2025·CVSS 6.3
CVE-2025-8885 [MEDIUM] CVE-2025-8885: bouncycastle - Allocation of Resources Without Limits or Throttling vulnerability in Legion of ...
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdenti... https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java . This issue affects BC Java: from 1.0 through 1.77; BC-FJA: from 1.0.0 through 1.0.2.5, from 2.0.0 through 2.0.1.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.80-1)
sid: resolved (fixed in 1.80-1)
trixie: resolved (fixed in 1.80-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-8885 resteasy: Bouncy Castle denial of service parsing ASN.1 Object Identifiers [fedora-42]
bugzilla·2025-08-12·CVSS 6.3
CVE-2025-8885 [MEDIUM] CVE-2025-8885 resteasy: Bouncy Castle denial of service parsing ASN.1 Object Identifiers [fedora-42]
CVE-2025-8885 resteasy: Bouncy Castle denial of service parsing ASN.1 Object Identifiers [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to c
Bugzilla
CVE-2025-8885 bouncycastle: Bouncy Castle denial of service parsing ASN.1 Object Identifiers
bugzilla·2025-08-12·CVSS 6.3
CVE-2025-8885 [MEDIUM] CVE-2025-8885 bouncycastle: Bouncy Castle denial of service parsing ASN.1 Object Identifiers
CVE-2025-8885 bouncycastle: Bouncy Castle denial of service parsing ASN.1 Object Identifiers
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java.
This issue affects Bouncy Castle for Java: from BC 1.0 through 1.77, from BC-FJA 1.0.0 through 2.0.0.
Discussion:
Jon, why did you file a report against the pdftk-java RPM package? The security flaw is in the bouncycastle RPM package, if I am not completely mistaken…
Bugzilla
CVE-2025-8885 apache-commons-vfs: Bouncy Castle denial of service parsing ASN.1 Object Identifiers [fedora-42]
bugzilla·2025-08-12·CVSS 6.3
CVE-2025-8885 [MEDIUM] CVE-2025-8885 apache-commons-vfs: Bouncy Castle denial of service parsing ASN.1 Object Identifiers [fedora-42]
CVE-2025-8885 apache-commons-vfs: Bouncy Castle denial of service parsing ASN.1 Object Identifiers [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's p
Bugzilla
CVE-2025-8885 pdftk-java: Bouncy Castle denial of service parsing ASN.1 Object Identifiers [fedora-42]
bugzilla·2025-08-12·CVSS 6.3
CVE-2025-8885 [MEDIUM] CVE-2025-8885 pdftk-java: Bouncy Castle denial of service parsing ASN.1 Object Identifiers [fedora-42]
CVE-2025-8885 pdftk-java: Bouncy Castle denial of service parsing ASN.1 Object Identifiers [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
Jon, why did you file this report against the pdftk-java RPM package? The security flaw is in the bouncycastle RPM package, if I am not completely mistaken…
---
This message is a rem
2025-08-12
Published