Description
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Published: 2026-08-03
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Bouncy Castle for Java before version 1.85, the ASN.1 parser contains a flaw that allows a lazily constructed sequence to reset the internal nesting‑depth guard. This behavior represents a CWE‑674 vulnerability, as it permits uncontrolled recursion and resource consumption. When a deeply nested or malformed ASN.1 structure is parsed, the guard can be bypassed, leading to uncontrolled recursion. The resulting excessive memory or stack usage can cause the application to become unresponsive or crash, effectively denying service to legitimate users.

Affected Systems

Affected products include Legion of the Bouncy Castle Inc.’s BC‑JAVA libraries for Java, the LTS releases prior to 2.73.12, and the Bouncy Castle for Java FIPS (BC‑FJA) before bc‑fips 1.0.2.7, 2.0.2 or 2.1.3.

Risk and Exploitability

The CVSS score of 8.7 marks this vulnerability as high severity. The EPSS score is 0.00263 and it is not listed in CISA’s KEV catalog, indicating no known widespread exploitation yet. The likely attack vector is from any entity that can supply or influence ASN.1 data processed by the library, which could be remote (e.g., via network) or local depending on the application context. If untrusted data is parsed, a malformed ASN.1 structure could trigger the recursion loop, exhausting resources and bringing the system down.

Generated by OpenCVE AI on August 4, 2026 at 22:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Bouncy Castle to version 1.85 or newer (BC‑JAVA), LTS 2.73.12 or newer, or FIPS 1.0.2.7/2.0.2/2.1.3 or newer.
  • Restrict ASN.1 parsing to data streams that are authenticated, authorized, and trusted to avoid processing untrusted inputs.
  • Instrument applications to monitor memory and stack usage during ASN.1 parsing, log any abnormal recursion depth or resource consumption, and apply defensive limits if the parser provides them.

Generated by OpenCVE AI on August 4, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-fja
Legion Of The Bouncy Castle Inc. bc-java
Legion Of The Bouncy Castle Inc. bc-lts-java
Vendors & Products Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-fja
Legion Of The Bouncy Castle Inc. bc-java
Legion Of The Bouncy Castle Inc. bc-lts-java

Mon, 03 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Description In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Title Lazy ASN.1 sequence forcing resets nesting-depth guard
Weaknesses CWE-674
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber'}


Subscriptions

Legion Of The Bouncy Castle Inc. Bc-fja Bc-java Bc-lts-java
cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-08-03T15:09:01.597Z

Reserved: 2026-06-28T04:39:00.599Z

Link: CVE-2026-13506

cve-icon Vulnrichment

Updated: 2026-08-03T15:08:51.533Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-03T04:16:39.957

Modified: 2026-08-04T14:50:12.360

Link: CVE-2026-13506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:15:03Z

Weaknesses