Excessive Resource Allocation Vulnerability in Bouncy Castle for Java by Legion of the Bouncy Castle Inc.
CVE-2025-8885

6.3MEDIUM

What is CVE-2025-8885?

A vulnerability in the Bouncy Castle for Java library, developed by Legion of the Bouncy Castle Inc., allows for excessive resource allocation. This issue affects all API modules in versions ranging from Bouncy Castle 1.0 to 1.77, and Bouncy Castle-FJA from 1.0.0 to 2.0.0. The vulnerability can lead to performance degradation or even system crashes if exploited, making it critical for developers to update to patched versions. Detailed technical information can be found in the official documentation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

BC Java All 1.0 <= 1.77

BC-FJA All 1.0.0 <= 1.0.2.5

BC-FJA All 2.0.0 <= 2.0.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bing Shi
.