CVE-2026-14682: Possible OOM from unbounded up-front allocation on a definite-length read
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14682?
CVE-2026-14682 has a severity rating of 8.7 on the CVSS scale, classified as high.
How do I fix CVE-2026-14682?
To fix CVE-2026-14682, update Bouncy Castle for Java to version 1.85 or later, or to the appropriate versions for LTS and FIPS as specified in the documentation.
What products are affected by CVE-2026-14682?
CVE-2026-14682 affects Bouncy Castle for Java, Bouncy Castle for Java LTS, and Bouncy Castle for Java FIPS in specific versions before their respective updates.
What does CVE-2026-14682 entail?
CVE-2026-14682 describes a potential out-of-memory (OOM) condition due to unbounded up-front allocation during a definite-length read in affected versions of Bouncy Castle.
Is there a workaround for CVE-2026-14682?
There is no documented workaround for CVE-2026-14682; the recommended action is to upgrade to a fixed version.