CVE-2026-17508: Password-based KDF cost parameters honoured unbounded from untrusted input across the remaining PBE entry points

Published Oct 2, 2026
·
Updated

In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an arbitrary amount of work before any password or integrity check could reject it. The affected paths are the RFC 9579 PBMAC1 MAC calculator builders, which took the PBKDF2 iteration count and derived-key length straight out of PBMAC1Params (JcePBMac1CalculatorBuilder, and PKCS12PBEUtils.createPBMac1Calculator reached from PKCS12PfxPdu.isMacValid); the scrypt parallelization parameter p in the PKCS#8 and PKCS#12 cost guards, which bounded only the cost parameter N and the block size r even though the scratch buffer scales with r times p, so the configured memory ceiling could be evaded entirely; the raw JCA PBKDF2 provider (org.bouncycastle.jcajce.provider.symmetric.PBEPBKDF2); and the bcrypt round count read from an encrypted OpenSSH v1 private key's own kdfoptions. Each now bounds the parameter before deriving, in line with the caps already applied elsewhere in the tree, with the OpenSSH round count configurable through the new org.bouncycastle.openssh.maxrounds property. This completes the bounding begun in 1.85 for the PKCS#8 / PBES2 decryptors (CVE-2026-15055). This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

Affected Software

3 affected components
Bouncy Castle Bouncy Castle for Java<1.86
Bouncy Castle Bouncy Castle for Java LTS<2.73.13
Bouncy Castle Bouncy Castle for Java FIPS (BC-FJA)<1.0.13, <2.0.13, <2.1.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Bouncy Castle for Java to a version that resolves this vulnerability.

    Fixed in 1.86
  2. Upgrade

    Upgrade Bouncy Castle for Java LTS to a version that resolves this vulnerability.

    Fixed in 2.73.13
  3. Upgrade

    Upgrade Bouncy Castle for Java FIPS (BC-FJA) 1.0.X series to a version that resolves this vulnerability.

    Fixed in 1.0.13
  4. Upgrade

    Upgrade Bouncy Castle for Java FIPS (BC-FJA) 2.0.X series to a version that resolves this vulnerability.

    Fixed in 2.0.13
  5. Upgrade

    Upgrade Bouncy Castle for Java FIPS (BC-FJA) 2.1.X series to a version that resolves this vulnerability.

    Fixed in 2.1.13

Event History

Oct 2, 2026
CVE Published
via MITRE·07:27 AM
Data Sourced
via MITRE·07:27 AM
DescriptionWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203