{"id":"CVE-2026-58063","summary":"BCFKS keystore load honours unbounded KDF cost from untrusted file","details":"In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","modified":"2026-08-08T19:03:20.841546823Z","published":"2026-08-03T02:29:09.708Z","related":["CGA-fq3m-m84v-79p6","openSUSE-SU-2026:11445-1","openSUSE-SU-2026:21538-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"1.0.0"},{"fixed":"1.0.2.7"},{"introduced":"2.0.0"},{"fixed":"2.0.2"},{"introduced":"2.1.0"},{"fixed":"2.1.3"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"bcorg","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58063.json"},"references":[{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-fips/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-lts/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58063.json"},{"type":"ADVISORY","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058063"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58063"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-lts-java"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bcgit/bc-java","events":[{"introduced":"0"},{"fixed":"57fbd3c501f7a369f64eda311d6a709fc0bcae84"},{"fixed":"81737a56ef4489da1f849cf549df95e338ea6b06"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.85"}],"source":["DESCRIPTION","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/bcgit/bc-lts-java","events":[{"introduced":"468b5082f3f0971e80bf9edb7029c17b39b9ba0c"},{"fixed":"f101b232c5d3e07ecdd504210a57e43831d6cd65"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2.73.0"},{"fixed":"2.73.12"}]}}],"versions":["r1rv84","r1rv81","r1rv83","r1rv82","r1rv80","r1rv78","r1rv77","r1rv76","r1rv75","r1rv74","r1rv73","r2rv73dot11","r2rv73dot10","r2rv73dot9","r2rv73dot8","r2rv73dot6","r2rv73dot4","r2rv73dot3","r2rv73dot1","r2rv73dot0"],"database_specific":{"vanir_signatures_modified":"2026-08-07T21:55:26Z","vanir_signatures":[{"source":"https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06","target":{"file":"core/src/main/java/org/bouncycastle/util/Properties.java"},"deprecated":false,"digest":{"line_hashes":["102651598719612461451204318068968325585","45230238234468642547860643575581980889","45297522555882596788886510719769951710"],"threshold":0.9},"id":"CVE-2026-58063-24a62c2a","signature_type":"Line","signature_version":"v1"},{"target":{"function":"performTest","file":"prov/src/test/java/org/bouncycastle/jce/provider/test/BCFKSStoreTest.java"},"deprecated":false,"digest":{"length":399,"function_hash":"97196642524409049649824429503537352657"},"id":"CVE-2026-58063-5c1fdcd3","signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06","target":{"file":"prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bcfks/BcFKSKeyStoreSpi.java"},"deprecated":false,"digest":{"line_hashes":["52735969277755972319211395169986010495","37930698598735065658556292559111878312","141114084220270166850116115141431571984","166035425026678193671729998394606564311","225626380489405269104715269151364318916","292634780617619332889139604890451192372","325956569862363410016853153935791915865","276115914328855788695834149212072069889","100429293740405568076594451812474225985","241760984190654916609945876961612791919","12298676889607508769847130270862071315","79810701464363562744460575882078485044","299340804217310855482500297926272283722","228555034051567588578380853872627580395","242441938689742431963436339022593438351","158298485265166454375483893411483821864","213923787035075464562176740043893479855","202700449113950706550844458781072309853","21870324310364645205116478137299433652","238445397402305358910154435405945210162","247391813297522763209654971806349487658"],"threshold":0.9},"id":"CVE-2026-58063-70b24ee7"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06","target":{"file":"prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bcfks/BcFKSKeyStoreSpi.java","function":"generateKey"},"deprecated":false,"digest":{"function_hash":"218960289093608826246302666792098092840","length":1904},"id":"CVE-2026-58063-8097358b"},{"deprecated":false,"digest":{"line_hashes":["338161456638555766921199886431436869791","173828105648014912990161709748026415950","97272610387377278181521148572206283987","242584727117918079787187061696704271203","42547155967706318575404851863590496751","157038091547283557145346192168268264519","247692343243261867057722127100943046923","134755098599701129349015599864694467487","30662707321350791038220568122002092172","31778482086692356249693773966818830123","149841401896403592467565652782917859241"],"threshold":0.9},"id":"CVE-2026-58063-d60b0397","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06","target":{"file":"prov/src/test/java/org/bouncycastle/jce/provider/test/BCFKSStoreTest.java"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58063.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Amber"}]}