CVE-2026-14682
published 2026-08-03CVE-2026-14682: In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.31%
23.5th percentile
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bctls-fips | < 1.0.24 | 1.0.24 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| bouncycastle | fips_java_api | >= 1.0.0 < 1.0.2.7 | 1.0.2.7 |
| bouncycastle | fips_java_api | >= 2.0.0 < 2.0.2 | 2.0.2 |
| bouncycastle | fips_java_api | >= 2.1.0 < 2.1.3 | 2.1.3 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.0 < 1.0.2.7 | 1.0.2.7 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.0 < 1.0.24 | 1.0.24 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.2 | 2.0.2 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.3 | 2.1.3 |
| legion_of_the_bouncy_castle_inc | bc-java | < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
| pki-core_10.6 | resteasy | — | — |
| pki-deps_10.6 | resteasy | — | — |
| redhat | resteasy | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read.
ghsa_unreviewed·2026-08-03
CVE-2026-14682 [HIGH] CWE-789 In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read.
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
Red Hat
org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bctls-fips: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation
vendor_redhat·2026-08-03·CVSS 8.7
CVE-2026-14682 [HIGH] CWE-770 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bctls-fips: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation
org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bctls-fips: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
A flaw was found in Bouncy Castle for Java, including its LTS and FIPS variants. This vulnerability allows a remote attacker to trigger an Out-Of-Memory (OOM) error by providing specially crafted input during a definite-length read operation. This unbounded memory allocation can lead to a Denia
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
blogs_hackernews·2026-08-24
CVE-2026-19478 ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.
That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.
Plenty to clean up. Here’s the short version.
## ⚡ Threat of the Week
U.S. Warns of AI-Powered Attacks on Siemens PLCs — Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series program
Bugzilla
CVE-2026-14682 jglobus: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation [fedora-all]
bugzilla·2026-08-25·CVSS 8.7
CVE-2026-14682 [HIGH] CVE-2026-14682 jglobus: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation [fedora-all]
CVE-2026-14682 jglobus: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
Bugzilla
CVE-2026-14682 resteasy: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation [fedora-all]
bugzilla·2026-08-25·CVSS 8.7
CVE-2026-14682 [HIGH] CVE-2026-14682 resteasy: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation [fedora-all]
CVE-2026-14682 resteasy: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
Bugzilla
CVE-2026-14682 byte-buddy: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation [fedora-all]
bugzilla·2026-08-25·CVSS 8.7
CVE-2026-14682 [HIGH] CVE-2026-14682 byte-buddy: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation [fedora-all]
CVE-2026-14682 byte-buddy: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
Bugzilla
CVE-2026-14682 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bctls-fips: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation
bugzilla·2026-08-03·CVSS 8.7
CVE-2026-14682 [HIGH] CVE-2026-14682 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bctls-fips: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation
CVE-2026-14682 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bctls-fips: Bouncy Castle for Java: Denial of Service due to unbounded memory allocation
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
2026-08-03
Published