CVE-2026-58063: BCFKS keystore load honours unbounded KDF cost from untrusted file
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58063?
The severity of CVE-2026-58063 is medium, with a CVSS score of 5.3.
How do I fix CVE-2026-58063?
To fix CVE-2026-58063, upgrade to Bouncy Castle for Java versions 1.85 or later, and ensure you are using the latest versions of Bouncy Castle LTS and BC-FJA.
What is the risk associated with CVE-2026-58063?
The risk associated with CVE-2026-58063 lies in the potential for an untrusted file to exploit the KDF cost settings, leading to denial of service attacks.
Which versions of Bouncy Castle are affected by CVE-2026-58063?
CVE-2026-58063 affects Bouncy Castle for Java versions before 1.85, Bouncy Castle LTS versions before 2.73.12, and BC-FJA versions before 1.0.2.7, 2.0.2, and 2.1.3.
What component is impacted by CVE-2026-58063?
CVE-2026-58063 impacts the BCFKS keystore loader in Bouncy Castle for Java.