{"id":"CVE-2026-15055","summary":"PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input","details":"In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).","modified":"2026-08-14T18:56:30.262310409Z","published":"2026-08-03T00:32:51.477Z","related":["SUSE-SU-2026:23127-1","SUSE-SU-2026:23150-1","SUSE-SU-2026:3559-1","openSUSE-SU-2026:11445-1","openSUSE-SU-2026:21538-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15055.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.0.0"},{"fixed":"1.0.12"},{"introduced":"2.0.0"},{"fixed":"2.0.12"},{"introduced":"2.1.0"},{"fixed":"2.1.12"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"bcorg","cwe_ids":["CWE-770"]},"references":[{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-fips/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-lts/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15055.json"},{"type":"ADVISORY","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9015055"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15055"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/7ab4ee67a0135950001b29b41a96d8a9a5d3b68b"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-lts-java"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bcgit/bc-java","events":[{"introduced":"0"},{"fixed":"57fbd3c501f7a369f64eda311d6a709fc0bcae84"},{"fixed":"7ab4ee67a0135950001b29b41a96d8a9a5d3b68b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.85"}],"source":["DESCRIPTION","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/bcgit/bc-lts-java","events":[{"introduced":"468b5082f3f0971e80bf9edb7029c17b39b9ba0c"},{"fixed":"f101b232c5d3e07ecdd504210a57e43831d6cd65"}],"database_specific":{"extracted_events":[{"introduced":"2.73.0"},{"fixed":"2.73.12"}],"source":"AFFECTED_FIELD"}}],"versions":["r1rv84","r1rv81","r1rv83","r1rv82","r1rv80","r1rv78","r1rv77","r1rv76","r1rv75","r1rv74","r1rv73","r2rv73dot11","r2rv73dot10","r2rv73dot9","r2rv73dot8","r2rv73dot6","r2rv73dot4","r2rv73dot3","r2rv73dot1","r2rv73dot0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-15055.json","vanir_signatures_modified":"2026-08-12T15:33:42Z","vanir_signatures":[{"id":"CVE-2026-15055-3819128d","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7ab4ee67a0135950001b29b41a96d8a9a5d3b68b","target":{"file":"pkix/src/main/java/org/bouncycastle/openssl/jcajce/JceOpenSSLPKCS8DecryptorProviderBuilder.java"},"deprecated":false,"digest":{"line_hashes":["197601844180946422528072632801533062252","327337482554323672876172753376894467444","12547090257679154677326366111840348967","147631208124227985361182938253039187504","216443469547609208047649654777064131371","32300303114783343026906264029296769906","36053410876470327639323494820696691394","264168430763772911908273459259711009186","149782471497434375155477884296336192643","337252166332478740207607050814704834059","255332732231301732805265389352388432113","106976234301705695119738664857589644739","42128709317077200414010668385289813866","156603104063162891903254229450296687906","114225595176719150098249388110617503619","334011374199697853356095028925987673673","63028674251518276049597088760895557383"],"threshold":0.9}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7ab4ee67a0135950001b29b41a96d8a9a5d3b68b","target":{"file":"pkix/src/main/java/org/bouncycastle/openssl/jcajce/JceOpenSSLPKCS8DecryptorProviderBuilder.java","function":"get"},"deprecated":false,"digest":{"length":2761,"function_hash":"40832651427481973368693959862750894414"},"id":"CVE-2026-15055-919bf1ee"},{"target":{"file":"core/src/main/java/org/bouncycastle/util/Properties.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["219299390001075404208844004346573718047","282853754084136645946883848581610034860","239715817206926481061699314304979199547"]},"id":"CVE-2026-15055-9edfc8be","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7ab4ee67a0135950001b29b41a96d8a9a5d3b68b"},{"signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7ab4ee67a0135950001b29b41a96d8a9a5d3b68b","target":{"file":"pkix/src/main/java/org/bouncycastle/pkcs/jcajce/JcePKCSPBEInputDecryptorProviderBuilder.java","function":"build"},"deprecated":false,"digest":{"function_hash":"121555780522040865491876521252916726998","length":4363},"id":"CVE-2026-15055-a67ea926","signature_type":"Function"},{"digest":{"threshold":0.9,"line_hashes":["192981730141668343278551779454961248728","35413633402855910819866114011773843195","208074935400963074346874336446894174805","328460629618389657995038008164699398566","48835025494704511195890396663336243095","152210190886018093757148921593991344883","241791045919716977020869152376131157700","84339301292373980554904505492176221356","206897602095088861226113850269676765141","148559173711510422050179560208490964519"]},"id":"CVE-2026-15055-af77d16b","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7ab4ee67a0135950001b29b41a96d8a9a5d3b68b","target":{"file":"pkix/src/test/java/org/bouncycastle/pkcs/test/PKCS8Test.java"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7ab4ee67a0135950001b29b41a96d8a9a5d3b68b","target":{"file":"pkix/src/main/java/org/bouncycastle/pkcs/jcajce/JcePKCSPBEInputDecryptorProviderBuilder.java"},"deprecated":false,"digest":{"line_hashes":["244357542669405217994751854049371298929","97435167411895865116636204817049188460","214100055610811312956723178543103903277","308420372358995995282052303790741162212","105887273748238508654712434661183725699","284509705648325219246628863733154819104","53351887287278262758133760316364720339","128773382095816364307612035541650542111","97286009600840289390498508297084944623","333568093544582207644708294366318881922","207844011521459936867991882173734881359","314254659918283838452420091833453504982","257895882147625575984690157239585916430","34554479903513392699700939905889928169","45581357658656217730625369506761969953","21475595178402264984770103600034501452","48135216922584214685782800718004391986","130218871610895781221827028910841125880","160973520838278077053182206439066415741","193945555105656936453847297800470789796","183325986263730029783145769233746546977"],"threshold":0.9},"id":"CVE-2026-15055-b1360dd1"},{"target":{"file":"pkix/src/main/java/org/bouncycastle/pkcs/jcajce/JcePKCSPBEInputDecryptorProviderBuilder.java","function":"get"},"deprecated":false,"digest":{"function_hash":"103019588276326492500981354270492834828","length":3321},"id":"CVE-2026-15055-b6a4f44f","signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7ab4ee67a0135950001b29b41a96d8a9a5d3b68b"},{"source":"https://github.com/bcgit/bc-java/commit/7ab4ee67a0135950001b29b41a96d8a9a5d3b68b","target":{"file":"pkix/src/main/java/org/bouncycastle/openssl/jcajce/JceOpenSSLPKCS8DecryptorProviderBuilder.java","function":"build"},"deprecated":false,"digest":{"function_hash":"33909541689866322411329461609305406313","length":3679},"id":"CVE-2026-15055-d04b3322","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Amber"}]}