An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Mar 19, 2025 | Mar 18, 2025 |
| Debian | — | Upgrade bouncycastle | May 15, 2025 | May 14, 2024 |
| Dell Powerstore Dsa2024462 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Nov 20, 2024 |
| Dell Powerstore Dsa2024497 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Dec 19, 2024 |
| Oracle Ebs | — | Apply the jan-2025 Critical Patch Update (CPU) (Patch ) for Oracle E-Business Suite | Feb 27, 2026 | Jan 14, 2025 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 37453807 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 37458537 for version 14.1.1.0.0. | Jan 21, 2025 | May 9, 2024 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jun 14, 2024 |
| Suse | — | Upgrade bouncycastle-pgUpgrade bouncycastle-mailUpgrade bouncycastle-pkixUpgrade bouncycastle-javadocUpgrade bouncycastleUpgrade bouncycastle-utilUpgrade bouncycastle-tlsUpgrade bouncycastle-jmail | Dec 5, 2025 | Dec 5, 2025 |
| Ubuntu | — | Upgrade libbctls-java (Ubuntu Pro)Upgrade libbcjmail-java (Ubuntu Pro)Upgrade libbcpkix-java (Ubuntu Pro)Upgrade libbcprov-java (Ubuntu Pro)Upgrade libbcpg-java (Ubuntu Pro)Upgrade libbcmail-java (Ubuntu Pro)Upgrade libbcutil-java (Ubuntu Pro) | Mar 19, 2026 | May 14, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub