Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java, https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java.
This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44 through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through 2.0.7.
CVSS Details
- CVSS 4.0 Base Score: 6.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:U/V:X/RE:M/U:Amber)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bouncycastle | Jul 23, 2026 | Jul 23, 2026 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 39163907 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 39164443 for version 14.1.1.0.0. | Apr 22, 2026 | Aug 13, 2025 |
| Red Hat Jboss Eap | — | — | Aug 14, 2025 | Aug 13, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Aug 13, 2025 |
| Ubuntu | — | Upgrade libbctls-java (Ubuntu Pro)Upgrade libbcpg-java (Ubuntu Pro)Upgrade libbcpkix-java (Ubuntu Pro)Upgrade libbcprov-java (Ubuntu Pro)Upgrade libbcmail-java (Ubuntu Pro)Upgrade libbcjmail-java (Ubuntu Pro)Upgrade libbcutil-java (Ubuntu Pro) | Mar 19, 2026 | Aug 13, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub