CVE-2025-8916
published 2025-08-13CVE-2025-8916: Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the…
PriorityP337medium6.3CVSS 4.0
AVNACLATPPRNUINVCNVINVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSPAUXRUVXREMUAmber
EPSS
0.46%
37.1th percentile
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java, https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java.
This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44 through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through 2.0.7.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bouncycastle | < bouncycastle 1.80-1 (forky) | bouncycastle 1.80-1 (forky) |
| legion_of_the_bouncy_castle_inc | bc_java | 1.44 – 1.78 | — |
| legion_of_the_bouncy_castle_inc | bcpkix_fips | 1.0.0 – 1.0.7 | — |
| legion_of_the_bouncy_castle_inc | bcpkix_fips | 2.0.0 – 2.0.7 | — |
CVSS provenance
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:U/V:X/RE:M/U:Amber
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
bouncycastle vulnerabilities
osv·2026-03-18·CVSS 5.3
CVE-2023-33201 [MEDIUM] bouncycastle vulnerabilities
bouncycastle vulnerabilities
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy Castle leaked timing information when
handling exceptions during an RSA
OSV
Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
osv·2025-08-13
CVE-2025-8916 [MEDIUM] Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertP... https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.java , https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathRevi... https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.java .
Thi
GHSA
Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
ghsa·2025-08-13
CVE-2025-8916 [MEDIUM] CWE-770 Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertP... https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.java , https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathRevi... https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.java .
Thi
OSV
CVE-2025-8916: Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc
osv·2025-08-13·CVSS 6.3
CVE-2025-8916 [MEDIUM] CVE-2025-8916: Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java, https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java. This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44 through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through 2.0.7.
Ubuntu
Bouncy Castle vulnerabilities
vendor_ubuntu·2026-03-18·CVSS 5.3
CVE-2025-8916 [MEDIUM] Bouncy Castle vulnerabilities
Title: Bouncy Castle vulnerabilities
Summary: Several security issues were fixed in Bouncy Castle.
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy
Oracle
Oracle Oracle Communications Risk Matrix: Core (Bouncy Castle Java Library) — CVE-2025-8916
vendor_oracle·2026-01-15·CVSS 2.4
CVE-2025-8916 [MEDIUM] Oracle Oracle Communications Risk Matrix: Core (Bouncy Castle Java Library) — CVE-2025-8916
Oracle Oracle Communications Risk Matrix: Core (Bouncy Castle Java Library) vulnerability
CVE: CVE-2025-8916
CVSS: 2.4
Protocol: HTTPS
Remote exploit: No
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Essbase Risk Matrix: Security and Provisioning (Bouncy Castle Java Library) — CVE-2025-8916
vendor_oracle·2025-10-15·CVSS 5.3
CVE-2025-8916 [MEDIUM] Oracle Oracle Essbase Risk Matrix: Security and Provisioning (Bouncy Castle Java Library) — CVE-2025-8916
Oracle Oracle Essbase Risk Matrix: Security and Provisioning (Bouncy Castle Java Library) vulnerability
CVE: CVE-2025-8916
CVSS: 5.3
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
org.bouncycastle: BouncyCastle denial of service
vendor_redhat·2025-08-13·CVSS 6.3
CVE-2025-8916 [MEDIUM] CWE-770 org.bouncycastle: BouncyCastle denial of service
org.bouncycastle: BouncyCastle denial of service
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java, https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java.
This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44 through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through 2.0.7.
A
Debian
CVE-2025-8916: bouncycastle - Allocation of Resources Without Limits or Throttling vulnerability in Legion of ...
vendor_debian·2025·CVSS 6.3
CVE-2025-8916 [MEDIUM] CVE-2025-8916: bouncycastle - Allocation of Resources Without Limits or Throttling vulnerability in Legion of ...
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java, https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java. This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44 through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through 2.0.7.
Scope: local
bookworm: open
bullseye: open
forky: re
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-8916 org.bouncycastle: BouncyCastle denial of service
bugzilla·2025-08-13·CVSS 6.3
CVE-2025-8916 [MEDIUM] CVE-2025-8916 org.bouncycastle: BouncyCastle denial of service
CVE-2025-8916 org.bouncycastle: BouncyCastle denial of service
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertP... https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.java , https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathRevi... https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.java .
This issue affects Bouncy Castle for Jav
Bugzilla
CVE-2025-8916 pdftk-java: BouncyCastle denial of service [fedora-42]
bugzilla·2025-08-13·CVSS 6.3
CVE-2025-8916 [MEDIUM] CVE-2025-8916 pdftk-java: BouncyCastle denial of service [fedora-42]
CVE-2025-8916 pdftk-java: BouncyCastle denial of service [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releas
Bugzilla
CVE-2025-8916 resteasy: BouncyCastle denial of service [fedora-42]
bugzilla·2025-08-13·CVSS 6.3
CVE-2025-8916 [MEDIUM] CVE-2025-8916 resteasy: BouncyCastle denial of service [fedora-42]
CVE-2025-8916 resteasy: BouncyCastle denial of service [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases
Bugzilla
CVE-2025-8916 apache-commons-vfs: BouncyCastle denial of service [fedora-42]
bugzilla·2025-08-13·CVSS 6.3
CVE-2025-8916 [MEDIUM] CVE-2025-8916 apache-commons-vfs: BouncyCastle denial of service [fedora-42]
CVE-2025-8916 apache-commons-vfs: BouncyCastle denial of service [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports fro
Bugzilla
CVE-2025-38081 kernel: spi-rockchip: Fix register out of bounds access
bugzilla·2025-06-18·CVSS 7.1
CVE-2025-38081 [HIGH] CVE-2025-38081 kernel: spi-rockchip: Fix register out of bounds access
CVE-2025-38081 kernel: spi-rockchip: Fix register out of bounds access
In the Linux kernel, the following vulnerability has been resolved:
spi-rockchip: Fix register out of bounds access
Do not write native chip select stuff for GPIO chip selects.
GPIOs can be numbered much higher than native CS.
Also, it makes no sense.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025061842-CVE-2025-38081-8916@gregkh/T
2025-08-13
Published