CVE-2026-59645
published 2026-08-03CVE-2026-59645: In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.31%
23.4th percentile
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bcutil-fips | >= 2.0.2 < 2.0.7 | 2.0.7 |
| bouncycastle | bcutil-fips | >= 2.1.4 < 2.1.7 | 2.1.7 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.7 | 2.0.7 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.7 | 2.1.7 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.70 < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
| pki-core_10.6 | resteasy | — | — |
| pki-deps_10.6 | resteasy | — | — |
| redhat | resteasy | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcutil-fips: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion
vendor_redhat·2026-08-03·CVSS 8.7
CVE-2026-59645 [HIGH] CWE-835 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcutil-fips: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion
org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcutil-fips: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
A flaw was found in Bouncy Castle for Java. A remote attacker could exploit this vulnerability by providing a specially crafted self-referential IEEE 1609.2 schema to the OER (Octet Encoding Rules) parser. This can cause the parser to recurse without a depth limit, leading to resource exhaustion and a denial of service (DoS) for the affected system.
Statement: B
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java FIPS up to 1.84/2.73.11/2.0.6/2.1.6 OER parser resource consumption
vuldb·2026-08-03·CVSS 8.7
CVE-2026-59645 [HIGH] Legion of the Bouncy Castle Bouncy Castle for Java FIPS up to 1.84/2.73.11/2.0.6/2.1.6 OER parser resource consumption
A vulnerability was found in Legion of the Bouncy Castle Bouncy Castle for Java FIPS, Bouncy Castle for Java LTS and Bouncy Castle for Java up to 1.84/2.73.11/2.0.6/2.1.6. It has been declared as problematic. This affects an unknown function of the component OER parser. Executing a manipulation can lead to resource consumption.
This vulnerability is handled as CVE-2026-59645. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema.
ghsa_unreviewed·2026-08-03
CVE-2026-59645 [HIGH] CWE-674 In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema.
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-59645 byte-buddy: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion [fedora-all]
bugzilla·2026-08-25·CVSS 8.7
CVE-2026-59645 [HIGH] CVE-2026-59645 byte-buddy: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion [fedora-all]
CVE-2026-59645 byte-buddy: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Bugzilla
CVE-2026-59645 jglobus: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion [fedora-all]
bugzilla·2026-08-25·CVSS 8.7
CVE-2026-59645 [HIGH] CVE-2026-59645 jglobus: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion [fedora-all]
CVE-2026-59645 jglobus: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Bugzilla
CVE-2026-59645 resteasy: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion [fedora-all]
bugzilla·2026-08-25·CVSS 8.7
CVE-2026-59645 [HIGH] CVE-2026-59645 resteasy: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion [fedora-all]
CVE-2026-59645 resteasy: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Bugzilla
CVE-2026-59645 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcutil-fips: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion
bugzilla·2026-08-03·CVSS 8.7
CVE-2026-59645 [HIGH] CVE-2026-59645 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcutil-fips: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion
CVE-2026-59645 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcutil-fips: Bouncy Castle for Java: Denial of Service via OER parser unbounded recursion
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
2026-08-03
Published