Home

Description

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdenti... https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java . This issue affects BC Java: from 1.0 through 1.77; BC-FJA: from 1.0.0 through 1.0.2.5, from 2.0.0 through 2.0.1.

PUBLISHED Reserved 2025-08-12 | Published 2025-08-12 | Updated 2025-09-12 | Assigner bcorg




MEDIUM: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/S:P/R:U/RE:M/U:Amber

Problem types

CWE-770 Allocation of Resources Without Limits or Throttling

Product status

Default status
unaffected

1.0
affected

Default status
unaffected

1.0.0
affected

2.0.0
affected

Credits

Bing Shi finder

References

github.com/bcgit/bc-java/wiki/CVE‐2025‐8885

cve.org (CVE-2025-8885)

nvd.nist.gov (CVE-2025-8885)

Download JSON