Password-Based Key Derivation Vulnerability in Bouncy Castle for Java
CVE-2026-97873
Key Information:
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-97873?
The raw JCA provider in Bouncy Castle for Java prior to 1.86 is susceptible to a password-based key derivation issue, where the legacy PBES1 and PKCS#12 PBE families process an iteration count derived from untrusted input without proper limitation. This oversight allows attackers to potentially manipulate the derivation process, resulting in excessive computational demands. Specifically, when using implementations like PKCS12PBE and its aliases, a count outside the safe range could inadvertently lead to performance-related Denial of Service, affecting the overall security mechanisms. The flaw has been addressed in subsequent releases by enforcing limits on input parameters, mitigating the risk associated with unbounded iteration counts.
Affected Version(s)
BC-JAVA all 0 < 1.86
BC-LTS-JAVA all 2.73.0 < 2.73.13
