Unbounded KDF Cost Issue in Bouncy Castle for Java
CVE-2026-58063
5.3MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2026-58063?
In Bouncy Castle for Java, an unbounded Key Derivation Function (KDF) cost can be triggered while loading a BCFKS keystore from an untrusted file. This compromises the application's security by potentially allowing an attacker to consume excessive resources during KDF operations, leading to Denial of Service (DoS) conditions. Affected versions include Bouncy Castle for Java versions prior to 1.85, as well as various LTS and FIPS iterations. It is crucial for users to update to resolved versions to mitigate potential risks.
Affected Version(s)
BC-FJA all 1.0.0 < 1.0.2.7
BC-FJA all 2.0.0 < 2.0.2
BC-FJA all 2.1.0 < 2.1.3
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Gaynor in collaboration with Claude and Anthropic Research
