Denial of Service Vulnerability in Bouncy Castle for Java
CVE-2026-13586

5.3MEDIUM

What is CVE-2026-13586?

A vulnerability exists in Bouncy Castle for Java prior to version 1.85 that can lead to a Denial of Service (DoS) condition. This issue arises from an improper handling of PKCS#12 MAC and bag-decryption Key Derivation Function (KDF) iteration-count, which can allow attackers to exploit the vulnerability and potentially disrupt services. It is also pertinent in the Long-Term Support (LTS) versions and specific FIPS configurations of Bouncy Castle prior to their respective patched versions.

Affected Version(s)

BC-FJA all 1.0.0 < 1.0.2.7

BC-FJA all 2.0.0 < 2.0.2

BC-FJA all 2.1.0 < 2.1.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.