Password-Based Key Derivation Vulnerability in Bouncy Castle for Java
CVE-2026-17508

5.3MEDIUM

What is CVE-2026-17508?

The vulnerability in Bouncy Castle for Java prior to version 1.86 allows attackers to manipulate password-based key derivation cost parameters using untrusted input. This can lead to excessive resource consumption during the key derivation process, as the implementation lacks necessary boundaries, enabling potentially unauthorized access or denial of service. Key functions such as PBMAC1, PBKDF2, and bcrypt within the library are affected, necessitating updates to ensure limits are enforced on critical parameters used for key derivation.

Affected Version(s)

BC-FJA all 1.0.0 < 1.0.13

BC-FJA all 2.0.0 < 2.0.13

BC-FJA all 2.1.0 < 2.1.13

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mirko Swillus on behalf of Alpha-Omega (alpha-omega.dev), using Scrutineer with an Anthropic Claude model provided through Project Glasswing
Yu Bao from the PayPal Cyber Security Team
.