CVE-2025-9092: Legion Of The Bouncy Castle Inc Bouncy Castle For Java - Bc-Fja 2.1.0

Low severity, CVSS 1.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader. This issue affects Bouncy Castle for Java - BC-FJA 2.1.0: from BC-FJA 2.1.0 through 2.1.0.

Affected products

Published 2025-08-16. Last modified 2026-06-17.