Uncontrolled Resource Consumption Vulnerability in Bouncy Castle for Java by Legion of the Bouncy Castle Inc.
CVE-2025-12194
5.9MEDIUM
Key Information:
- Vendor
- CVE Published:
- 24 October 2025
What is CVE-2025-12194?
This vulnerability arises from excessive resource allocation in Bouncy Castle for Java, particularly in its encryption and hashing modules. It impacts several API files across both the FIPS and LTS versions of Bouncy Castle, potentially allowing attackers to exploit this flaw for denial of service attacks or to exhaust system resources. Developers and organizations using the Bouncy Castle libraries should prioritize updates to mitigate these risks, as this vulnerability could lead to significant operational impairments.
Affected Version(s)
Bouncy Castle for Java FIPS All 2.1.0 <= 2.1.1
Bouncy Castle for Java LTS All 2.73.0 <= 2.73.7
