Allocation of Resources Without Limits or Throttling in Bouncy Castle for Java - CVE-2025-8916

 

Allocation of Resources Without Limits or Throttling in Bouncy Castle for Java - CVE-2025-8916

Published: October 21, 2025 / Updated: May 25, 2026


Vulnerability identifier: #VU117436
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-8916
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to improper resource allocation. A remote attacker can library to consume excessive resources and perform a denial of service attack. 


Affected software

Bouncy Castle for Java
IBM Disconnected Log Collector
IBM App Connect for Manufacturing
DataPower Operations Dashboard
Storage Defender - Resiliency Service
DevOps
Maximo Application Suite - IoT Component
Maximo Application Suite - Predict Component
Rational Performance Tester
Integration Bus for z/OS
DevOps Test Performance
ApplinX
Cloudera Observability with IBM
StreamSets Data Collector
Guardium Data Protection
IBM Observability with Instana
Netcool Operations Insight
IBM Sterling Secure Proxy
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling External Authentication Server
IBM UrbanCode Release
IBM Spectrum Symphony
IBM Security Verify Governance
Oracle Middleware Common Libraries and Tools
Splunk AppDynamics Database Agent
Oracle Communications Cloud Native Core Certificate Management
IBM Cloud Object Storage Systems
watsonx.data
Oracle Utilities Application Framework
Oracle Global Lifecycle Management NextGen OUI Framework
Communications Unified Assurance
IBM License Metric Tool
IBM DB2
Oracle GoldenGate Big Data and Application Adapters
Oracle Essbase
IBM App Connect Enterprise
Oracle WebLogic Server
Ubuntu
Anolis OS
Siebel CRM Deployment
bouncycastle (Ubuntu package)
bouncycastle-javadoc
bouncycastle
bouncycastle-util
bouncycastle-tls
bouncycastle-pkix
bouncycastle-pg
bouncycastle-mail
bouncycastle-jmail

How to mitigate CVE-2025-8916

Install updates from vendor's website.

Bouncy Castle for Java - update to 1.79
IBM Disconnected Log Collector - update to 2.0.0
DataPower Operations Dashboard - update to 1.0.23.3
IBM Observability with Instana - update to 1.0.307
Netcool Operations Insight - update to 1.6.15
Storage Defender - Resiliency Service - update to 2.0.18
IBM Sterling Secure Proxy - addressed in versions 6.1.0.3, 6.2.0.3, 6.2.1.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.2
IBM Sterling External Authentication Server - addressed in versions 6.1.0.4, 6.1.1.1
DevOps - update to 7.0.0.6
IBM Spectrum Symphony - update to 7.3.2 FP3
Maximo Application Suite - IoT Component - addressed in versions 8.7.29, 8.8.26, 9.0.15, 9.1.6
Maximo Application Suite - Predict Component - addressed in versions 8.8.12, 8.9.14, 9.0.11, 9.1.4
IBM License Metric Tool - update to 9.2.42
IBM Security Verify Governance - update to 10.0.2.0.7
Integration Bus for z/OS - update to 10.1.0.6
DevOps Test Performance - update to 11.0.7
IBM App Connect Enterprise - addressed in versions 12.0.12.17, 13.0.5.0
Splunk AppDynamics Database Agent - update to 26.1.0
bouncycastle (Ubuntu package) - addressed in versions 1.51-4ubuntu1+esm1, 1.59-1ubuntu0.1~esm1, 1.61-1ubuntu0.1~esm1, 1.68-5ubuntu0.1~esm1, 1.77-1ubuntu0.1~esm1
bouncycastle-javadoc - update to 1.79-1
bouncycastle - update to 1.79-1
bouncycastle-util - update to 1.79-1
bouncycastle-tls - update to 1.79-1
bouncycastle-pkix - update to 1.79-1
bouncycastle-pg - update to 1.79-1
bouncycastle-mail - update to 1.79-1
bouncycastle-jmail - update to 1.79-1
Cloudera Observability with IBM - update to 3.6.2
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
StreamSets Data Collector - update to 6.4.0
Guardium Data Protection - addressed in versions 12.0p55, 12.0p140, 12.2.1

External References

Related Security Bulletins