Denial of Service Vulnerability in Bouncy Castle for Java SSL/TSL Library
CVE-2026-17507

8.7HIGH

What is CVE-2026-17507?

A vulnerability exists in Bouncy Castle for Java prior to version 1.86, where the MLS implementation incorrectly handles the uint32 leaf_index, leading to potential denial of service. Specifically, the use of a signed int for decoding can result in negative comparisons during group validation checks. This flaw permits an out-of-range sender to bypass membership validation, which can allow any current group member to send a small message that may exhaust the JVM's heap, thereby disrupting service for all group members. This issue has been addressed in version 1.86, which now process the leaf indices as unsigned, ensuring that any out-of-range values are correctly rejected.

Affected Version(s)

BC-JAVA all 1.73 < 1.86

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mirko Swillus on behalf of Alpha-Omega (alpha-omega.dev), using Scrutineer with an Anthropic Claude model provided through Project Glasswing
.