{"id":"GHSA-jv6h-4262-q663","summary":"Bouncy Castle Vulnerable to Uncontrolled Resource Consumption","details":"Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files core/src/main/jdk1.9/org/bouncycastle/crypto/fips/AESNativeCFB.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/fips/AESNativeGCM.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/fips/SHA256NativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/fips/AESNativeEngine.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/fips/AESNativeCBC.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/fips/AESNativeCTR.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeCFB.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeGCM.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeEngine.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeCBC.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeGCMSIV.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeCCM.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/engines/AESNativeCTR.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHA256NativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHA224NativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHA3NativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHAKENativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHA512NativeDigest.Java, core/src/main/jdk1.9/org/bouncycastle/crypto/digests/SHA384NativeDigest.Java.\n\nThis issue affects Bouncy Castle for Java FIPS: from 2.1.0 through 2.1.1; Bouncy Castle for Java LTS: from 2.73.0 through 2.73.7.","aliases":["CVE-2025-12194"],"modified":"2026-09-10T03:50:30.013697119Z","published":"2025-10-25T00:30:39Z","database_specific":{"nvd_published_at":"2025-10-24T23:15:39Z","cwe_ids":["CWE-400"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-10-28T17:48:24Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12194"},{"type":"WEB","url":"https://github.com/bcgit/bc-lts-java/commit/2c9be6c64152ce48c6afc784c042a514be71ec71"},{"type":"WEB","url":"https://github.com/bcgit/bc-lts-java/commit/f2776feac0c30230f7a5ac34eb24f5019caf0324"},{"type":"WEB","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9012194"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-lts-java"}],"affected":[{"package":{"name":"org.bouncycastle:bc-fips","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bc-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.2"}]}],"versions":["2.1.0","2.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-jv6h-4262-q663/GHSA-jv6h-4262-q663.json","last_known_affected_version_range":"\u003c= 2.1.1"}},{"package":{"name":"org.bouncycastle:bcprov-debug-lts8on","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bcprov-debug-lts8on"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.73.0"},{"fixed":"2.73.8"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.73.7","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-jv6h-4262-q663/GHSA-jv6h-4262-q663.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:C/RE:M/U:Amber"}]}