CVE-2026-15055
published 2026-08-03CVE-2026-15055: In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS…
PriorityP345high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.27%
18.9th percentile
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bcpkix-fips | < 1.0.12 | 1.0.12 |
| bouncycastle | bcpkix-fips | >= 2.0.7 < 2.0.12 | 2.0.12 |
| bouncycastle | bcpkix-fips | >= 2.1.8 < 2.1.12 | 2.1.12 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| debian | ceph | — | — |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.0 < 1.0.12 | 1.0.12 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.12 | 2.0.12 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.12 | 2.1.12 |
| legion_of_the_bouncy_castle_inc | bc-java | < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
| pki-core_10.6 | resteasy | — | — |
| pki-deps_10.6 | resteasy | — | — |
| redhat | resteasy | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bcpkix-fips: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8
vendor_redhat·2026-08-03·CVSS 5.3
CVE-2026-15055 [MEDIUM] CWE-770 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bcpkix-fips: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8
org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bcpkix-fips: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
A flaw was found in Bouncy Castle for Java. An attacker could exploit this vulnerability by providing a specially crafted input to the PKCS#8 / PBES2 decryptors. This input could specify an excessively high Key Derivation Function (KDF) cost, causing the decryptor to consume s
GHSA
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input.
ghsa_unreviewed·2026-08-03
CVE-2026-15055 [MEDIUM] CWE-770 In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input.
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java up to 2.1.11 PKCS#8/PBES2 Decryptors allocation of resources
vuldb·2026-08-03·CVSS 5.3
CVE-2026-15055 [MEDIUM] Legion of the Bouncy Castle Bouncy Castle for Java up to 2.1.11 PKCS#8/PBES2 Decryptors allocation of resources
A vulnerability was found in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS up to 1.84/2.73.11/1.0.11/2.0.11/2.1.11. It has been rated as problematic. This impacts an unknown function of the component PKCS#8/PBES2 Decryptors. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2026-15055. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-15055 byte-buddy: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
bugzilla·2026-08-25·CVSS 5.3
CVE-2026-15055 [MEDIUM] CVE-2026-15055 byte-buddy: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
CVE-2026-15055 byte-buddy: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Bugzilla
CVE-2026-15055 jglobus: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
bugzilla·2026-08-25·CVSS 5.3
CVE-2026-15055 [MEDIUM] CVE-2026-15055 jglobus: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
CVE-2026-15055 jglobus: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Bugzilla
CVE-2026-15055 ceph: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
bugzilla·2026-08-25·CVSS 5.3
CVE-2026-15055 [MEDIUM] CVE-2026-15055 ceph: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
CVE-2026-15055 ceph: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Bugzilla
CVE-2026-15055 resteasy: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
bugzilla·2026-08-25·CVSS 5.3
CVE-2026-15055 [MEDIUM] CVE-2026-15055 resteasy: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
CVE-2026-15055 resteasy: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Bugzilla
CVE-2026-15055 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bcpkix-fips: Bouncy Castle for Java: Denial of service due to unbounded KDF
bugzilla·2026-08-03·CVSS 5.3
CVE-2026-15055 [MEDIUM] CVE-2026-15055 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bcpkix-fips: Bouncy Castle for Java: Denial of service due to unbounded KDF
CVE-2026-15055 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bc-fips: org.bouncycastle/bcpkix-fips: Bouncy Castle for Java: Denial of service due to unbounded KDF cost in PKCS#8 / PBES2 decryptors
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Wiz
CVE-2025-15055 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.2
CVE-2025-15055 [HIGH] CVE-2025-15055 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15055 :
WordPress vulnerability analysis and mitigation
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' parameters in all versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the Recent Custom Events report.
Source : NVD
## 7.2
Score
Published January 9, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
WordPress
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.4
Exploitation Probability (EPSS) N/A
Affected
2026-08-03
Published