Denial of Service Vulnerability in Bouncy Castle for Java
CVE-2026-13586
5.3MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2026-13586?
A vulnerability exists in Bouncy Castle for Java prior to version 1.85 that can lead to a Denial of Service (DoS) condition. This issue arises from an improper handling of PKCS#12 MAC and bag-decryption Key Derivation Function (KDF) iteration-count, which can allow attackers to exploit the vulnerability and potentially disrupt services. It is also pertinent in the Long-Term Support (LTS) versions and specific FIPS configurations of Bouncy Castle prior to their respective patched versions.
Affected Version(s)
BC-FJA all 1.0.0 < 1.0.2.7
BC-FJA all 2.0.0 < 2.0.2
BC-FJA all 2.1.0 < 2.1.3
