{"id":"GHSA-4cx2-fc23-5wg6","summary":"Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation","details":"Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files  https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertP... https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.java ,  https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathRevi... https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.java .\n\nThis issue affects Bouncy Castle for Java: from BC 1.44 through 1.78, from BCPKIX FIPS 1.0.0 through 1.0.7, from BCPKIX FIPS 2.0.0 through 2.0.7.","aliases":["CVE-2025-8916"],"modified":"2026-07-17T21:09:35.459944063Z","published":"2025-08-13T12:31:30Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-08-13T22:52:42Z","nvd_published_at":"2025-08-13T10:15:27Z","cwe_ids":["CWE-770"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8916"},{"type":"WEB","url":"https://github.com/bcgit/bc-java/commit/310b30a4fbf36d13f6cc201ffa7771715641e67e"},{"type":"WEB","url":"https://github.com/bcgit/bc-java/commit/ff444a479942d88de64004dc82c3ee32a9e9075a"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"},{"type":"WEB","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%908916"}],"affected":[{"package":{"name":"org.bouncycastle:bcpkix-jdk15on","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bcpkix-jdk15on"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.44"},{"fixed":"1.79"}]}],"versions":["1.47","1.48","1.49","1.50","1.51","1.52","1.53","1.54","1.55","1.56","1.57","1.58","1.59","1.60","1.61","1.62","1.63","1.64","1.65","1.66","1.67","1.68","1.69","1.70"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4cx2-fc23-5wg6/GHSA-4cx2-fc23-5wg6.json"}},{"package":{"name":"org.bouncycastle:bcpkix-jdk15to18","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bcpkix-jdk15to18"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.44"},{"fixed":"1.79"}]}],"versions":["1.63","1.64","1.65","1.66","1.67","1.68","1.69","1.70","1.71","1.72","1.73","1.74","1.75","1.76","1.77","1.78","1.78.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4cx2-fc23-5wg6/GHSA-4cx2-fc23-5wg6.json"}},{"package":{"name":"org.bouncycastle:bcpkix-jdk18on","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bcpkix-jdk18on"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.44"},{"fixed":"1.79"}]}],"versions":["1.71","1.71.1","1.72","1.73","1.74","1.75","1.76","1.77","1.78","1.78.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4cx2-fc23-5wg6/GHSA-4cx2-fc23-5wg6.json"}},{"package":{"name":"org.bouncycastle:bcpkix-fips","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bcpkix-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.0.8"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.0.7","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4cx2-fc23-5wg6/GHSA-4cx2-fc23-5wg6.json"}},{"package":{"name":"org.bouncycastle:bcpkix-fips","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bcpkix-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.8"}]}],"versions":["2.0.7"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.7","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4cx2-fc23-5wg6/GHSA-4cx2-fc23-5wg6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/S:P/R:U/RE:M/U:Amber"}]}