Resource exhaustion in Bouncy Castle for Java FIPS and Bouncy Castle for Java LTS - CVE-2025-12194

 

Resource exhaustion in Bouncy Castle for Java FIPS and Bouncy Castle for Java LTS - CVE-2025-12194

Published: May 25, 2026


Vulnerability identifier: #VU132271
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-12194
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in API modules when processing crafted input that triggers excessive allocation. A remote attacker can send crafted input to cause a denial of service.

The issue is associated with multiple AES and SHA native implementation files.


Affected software

Bouncy Castle for Java FIPS
Bouncy Castle for Java LTS

How to mitigate CVE-2025-12194

Install security update from vendor's website.

Bouncy Castle for Java FIPS - update to 2.1.1
Bouncy Castle for Java LTS - update to 2.73.7

External References

Related Security Bulletins