Uncontrolled Resource Consumption Vulnerability in Bouncy Castle for Java by Legion of the Bouncy Castle Inc.
CVE-2025-12194
Key Information:
- Vendor
- CVE Published:
- 24 October 2025
What is CVE-2025-12194?
This vulnerability arises from excessive resource allocation in Bouncy Castle for Java, particularly in its encryption and hashing modules. It impacts several API files across both the FIPS and LTS versions of Bouncy Castle, potentially allowing attackers to exploit this flaw for denial of service attacks or to exhaust system resources. Developers and organizations using the Bouncy Castle libraries should prioritize updates to mitigate these risks, as this vulnerability could lead to significant operational impairments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Bouncy Castle for Java FIPS All 2.1.0 <= 2.1.1
Bouncy Castle for Java LTS All 2.73.0 <= 2.73.7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
