Resource exhaustion in Bouncy Castle for Java FIPS and Bouncy Castle for Java LTS - CVE-2025-12194
Published: May 25, 2026
Bouncy Castle for Java FIPS
Bouncy Castle for Java LTS
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in API modules when processing crafted input that triggers excessive allocation. A remote attacker can send crafted input to cause a denial of service.
The issue is associated with multiple AES and SHA native implementation files.