CVE-2026-13506
published 2026-08-03CVE-2026-13506: In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.31%
23.5th percentile
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| bouncycastle | fips_java_api | >= 1.0.0 < 1.0.2.7 | 1.0.2.7 |
| bouncycastle | fips_java_api | >= 2.0.0 < 2.0.2 | 2.0.2 |
| bouncycastle | fips_java_api | >= 2.1.0 < 2.1.3 | 2.1.3 |
| jboss-eap-7 | eap74-els-openjdk11-openshift-rhel8 | — | — |
| jboss-eap-7 | eap74-els-openjdk17-openshift-rhel8 | — | — |
| jboss-eap-7 | eap74-els-openjdk8-openshift-rhel8 | — | — |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.0 < 1.0.2.7 | 1.0.2.7 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.2 | 2.0.2 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.3 | 2.1.3 |
| legion_of_the_bouncy_castle_inc | bc-java | < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard.
ghsa_unreviewed·2026-08-03
CVE-2026-13506 [HIGH] CWE-674 In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard.
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Red Hat
bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing
vendor_redhat·2026-08-03·CVSS 7.5
CVE-2026-13506 [HIGH] CWE-770 bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing
bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
A flaw was found in Bouncy Castle for Java. A remote attacker could exploit a vulnerability related to how the software processes lazy ASN.1 sequences, which can reset an internal nesting-depth guard. This issue could lead to a Denial of Service (DoS), making the affected system or application unavailable.
Statement: This Important flaw in Bouncy Castle for Java can lead to a denial of service. A remote attacker c
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-13506 bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing [epel-all]
bugzilla·2026-08-27·CVSS 7.5
CVE-2026-13506 [HIGH] CVE-2026-13506 bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing [epel-all]
CVE-2026-13506 bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Bugzilla
CVE-2026-13506 bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing [fedora-all]
bugzilla·2026-08-27·CVSS 7.5
CVE-2026-13506 [HIGH] CVE-2026-13506 bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing [fedora-all]
CVE-2026-13506 bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Bugzilla
CVE-2026-13506 bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing
bugzilla·2026-08-03·CVSS 7.5
CVE-2026-13506 [HIGH] CVE-2026-13506 bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing
CVE-2026-13506 bouncycastle: Bouncy Castle for Java: Denial of Service via lazy ASN.1 sequence processing
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
2026-08-03
Published