Maven: org.bouncycastle:bc-fips
CVE-2026-14682
Safety vulnerability ID: SFTY-20260803-82847
Affected versions of the `org.bouncycastle:bcprov-jdk18on` package are vulnerable to Denial of Service (DoS) due to improper handling of ASN.1 definite-length reads. The `ASN.1` parser allocates memory based on the length specified in the encoding without verifying it against the actual data available, leading to potential memory exhaustion. An attacker can exploit this vulnerability by providing a short ASN.1 input with a falsely large length, causing the process to allocate excessive memory and potentially exhaust the heap, resulting in a denial of service.
Overview
org.bouncycastle:bcprov-jdk18on – Memory Allocation with Excessive Size Value
Advisory
org.bouncycastle:bcprov-jdk18on – Memory Allocation with Excessive Size Value
Affected Package
Also affects
---
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more