Maven: org.bouncycastle:bc-fips

CVE-2026-14682

Safety vulnerability ID: SFTY-20260803-82847

Affected versions of the `org.bouncycastle:bcprov-jdk18on` package are vulnerable to Denial of Service (DoS) due to improper handling of ASN.1 definite-length reads. The `ASN.1` parser allocates memory based on the length specified in the encoding without verifying it against the actual data available, leading to potential memory exhaustion. An attacker can exploit this vulnerability by providing a short ASN.1 input with a falsely large length, causing the process to allocate excessive memory and potentially exhaust the heap, resulting in a denial of service.

Created at: Sep 10, 2026Updated at: Sep 10, 2026

Overview

org.bouncycastle:bcprov-jdk18on – Memory Allocation with Excessive Size Value

Advisory

org.bouncycastle:bcprov-jdk18on – Memory Allocation with Excessive Size Value

Affected Package

Affecting org.bouncycastle:bc-fips package, versions< 1.0.2.7>= 2.0.0, < 2.0.2>= 2.1.0, < 2.1.3

Also affects

---

How to Fix

Upgradeorg.bouncycastle:bc-fipsto1.0.2.72.0.22.1.3or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more