5.3
CVE-2026-58063
- EPSS 0.33%
- Veröffentlicht 03.08.2026 02:29:09
- Zuletzt bearbeitet 02.09.2026 14:34:30
- Erkennungen
BCFKS keystore load honours unbounded KDF cost from untrusted file
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bouncycastle ≫ Bc-java Version < 1.85
Bouncycastle ≫ Bouncy Castle For Java Lts Version <= 2.73.11
Bouncycastle ≫ Fips Java Api Version >= 1.0.0 < 1.0.2.7
Bouncycastle ≫ Fips Java Api Version >= 2.0.0 < 2.0.2
Bouncycastle ≫ Fips Java Api Version >= 2.1.0 < 2.1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.255 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
| 91579145-5d7b-4cc5-b925-a0262ff19630 | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058063