CVE-2025-9092: Hybrid Module Deployment in Multi-JVM Environments Leading to Resource Exhaustion
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader.
This issue affects Bouncy Castle for Java - BC-FJA 2.1.0: from BC-FJA 2.1.0 through 2.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9092?
CVE-2025-9092 is classified as a moderate severity vulnerability due to its potential for excessive resource consumption.
How do I fix CVE-2025-9092?
To mitigate CVE-2025-9092, update Bouncy Castle for Java - BC-FJA to a version higher than 2.1.0.
What impact does CVE-2025-9092 have on applications?
CVE-2025-9092 can lead to excessive allocation of resources, potentially causing denial of service in applications using the affected version.
Which versions of Bouncy Castle are affected by CVE-2025-9092?
CVE-2025-9092 affects Bouncy Castle for Java - BC-FJA version 2.1.0.
Is CVE-2025-9092 an active vulnerability?
As of now, CVE-2025-9092 is known but organizations should verify their exposure and apply updates to protect against potential exploitation.