CVE-2025-8885: Legion Of The Bouncy Castle Inc Bc-Fja
Medium severity, CVSS 6.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdenti... https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java . This issue affects BC Java: from 1.0 through 1.77; BC-FJA: from 1.0.0 through 1.0.2.5, from 2.0.0 through 2.0.1.
Affected products
- Legion Of The Bouncy Castle Inc Bc-Fja: from 1.0.0, up to and including 1.0.2.5; from 2.0.0, up to and including 2.0.1
- Legion Of The Bouncy Castle Inc Bc Java: from 1.0, up to and including 1.77
Published 2025-08-12. Last modified 2026-06-17.