216.73.216.36

CVE-2025-8916

· Published 13/08/2025 10:15 · Modified 13/08/2025 17:33

Labels: CVE-2025-8916 2025-08-1391579145-5d7b-4cc5-b925-a0262ff19630CVE-2025-8916CWE-770

Essential information

Published
13/08/2025 10:15
Modified
13/08/2025 17:33
Author
Creator
CVSS
6.3 MEDIUM (v3) 6.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertP... https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.java , https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathRevi... https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.java . This issue affects Bouncy Castle for Java: from BC 1.44 through 1.78, from BCPKIX FIPS 1.0.0 through 1.0.7, from BCPKIX FIPS 2.0.0 through 2.0.7.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
91579145-5d7b-4cc5-b925-a0262ff19630
NVD
View on NVD

Affected products (CPE)

ProductCPE
legion of the bouncy castle inc / bouncy castle for java cpe:2.3:a:legion_of_the_bouncy_castle_inc:bouncy_castle_for_java:1.44-1.78:*:*:*:*:*:*:*
legion of the bouncy castle inc / bcpkix fips cpe:2.3:a:legion_of_the_bouncy_castle_inc:bcpkix_fips:1.0.0-1.0.7:*:*:*:*:*:*:*
legion of the bouncy castle inc / bcpkix fips cpe:2.3:a:legion_of_the_bouncy_castle_inc:bcpkix_fips:2.0.0-2.0.7:*:*:*:*:*:*:*

References