Excessive Resource Allocation Vulnerability in Bouncy Castle for Java by Legion of the Bouncy Castle Inc.
CVE-2025-8885
Key Information:
- Vendor
- CVE Published:
- 12 August 2025
What is CVE-2025-8885?
A vulnerability in the Bouncy Castle for Java library, developed by Legion of the Bouncy Castle Inc., allows for excessive resource allocation. This issue affects all API modules in versions ranging from Bouncy Castle 1.0 to 1.77, and Bouncy Castle-FJA from 1.0.0 to 2.0.0. The vulnerability can lead to performance degradation or even system crashes if exploited, making it critical for developers to update to patched versions. Detailed technical information can be found in the official documentation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BC Java All 1.0 <= 1.77
BC-FJA All 1.0.0 <= 1.0.2.5
BC-FJA All 2.0.0 <= 2.0.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
