CVE-2025-8916: Legion Of The Bouncy Castle Inc Bc Java
Medium severity, CVSS 6.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java, https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java. This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44 through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through 2.0.7.
Affected products
- Legion Of The Bouncy Castle Inc Bc Java: from 1.44, up to and including 1.78
- Legion Of The Bouncy Castle Inc Bcpkix Fips: from 1.0.0, up to and including 1.0.7; from 2.0.0, up to and including 2.0.7
- Siemens SIMATIC Cn 4100: before V5.0 (fixed in V5.0)
Published 2025-08-13. Last modified 2026-06-17.