๐Ÿ” CVE Alert

CVE-2025-8916

UNKNOWN 0.0

Possible DOS in processing large name constraint structures in PKIXCertPathReveiwer

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java, https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java. This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44 through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through 2.0.7.

CWE CWE-770
Vendor legion of the bouncy castle inc.
Product bc java
Published Aug 13, 2025
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for legion of the bouncy castle inc. bc java

Be the first to know when new unknown vulnerabilities affecting legion of the bouncy castle inc. bc java are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Legion of the Bouncy Castle Inc. / BC Java
1.44 โ‰ค 1.78
Legion of the Bouncy Castle Inc. / BC Java
1.44 โ‰ค 1.78
Legion of the Bouncy Castle Inc. / BCPKIX FIPS
1.0.0 โ‰ค 1.0.7 2.0.0 โ‰ค 2.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%908916 cert-portal.siemens.com: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

Credits

Bing Shi