CVE-2025-12194: Medium severity Legion of the Bouncy Castle Bouncy Castle for Java FIPS vulnerability
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files core/src/main/jdk1.9/org/bouncycastle/crypto/fips/AESNativeCFB.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/fips/AESNativeGCM.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/fips/SHA256NativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/fips/AESNativeEngine.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/fips/AESNativeCBC.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/fips/AESNativeCTR.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeCFB.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeGCM.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeEngine.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeCBC.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeGCMSIV.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeCCM.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeCTR.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHA256NativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHA224NativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHA3NativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHAKENativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHA512NativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHA384NativeDigest.Java.
This issue affects Bouncy Castle for Java FIPS: from 2.1.0 through 2.1.1; Bouncy Castle for Java LTS: from 2.73.0 through 2.73.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.bouncycastle:bcprov-debug-lts8onto a version that resolves this vulnerability.Fixed in 2.73.8 - Upgrade
Upgrade
maven/org.bouncycastle:bc-fipsto a version that resolves this vulnerability.Fixed in 2.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12194?
CVE-2025-12194 has been classified as a high severity vulnerability due to its potential for excessive resource allocation.
How do I fix CVE-2025-12194?
To fix CVE-2025-12194, update to the latest version of Bouncy Castle for Java FIPS or Bouncy Castle for Java LTS that includes the security patch.
What products are affected by CVE-2025-12194?
CVE-2025-12194 affects all versions of Bouncy Castle for Java FIPS and Bouncy Castle for Java LTS.
What are the potential impacts of CVE-2025-12194?
The potential impacts of CVE-2025-12194 include denial of service due to uncontrolled resource consumption.
Is there a workaround for CVE-2025-12194?
Currently, there are no known workarounds for CVE-2025-12194 other than applying the available patches.