Denial of Service Vulnerability in Bouncy Castle for Java SSL/TSL Library
CVE-2026-17507
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-17507?
A vulnerability exists in Bouncy Castle for Java prior to version 1.86, where the MLS implementation incorrectly handles the uint32 leaf_index, leading to potential denial of service. Specifically, the use of a signed int for decoding can result in negative comparisons during group validation checks. This flaw permits an out-of-range sender to bypass membership validation, which can allow any current group member to send a small message that may exhaust the JVM's heap, thereby disrupting service for all group members. This issue has been addressed in version 1.86, which now process the leaf indices as unsigned, ensuring that any out-of-range values are correctly rejected.
Affected Version(s)
BC-JAVA all 1.73 < 1.86
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
