Bouncy Castle for Java on All (API modules) allows Excessive Allocation (CVE-2025-8885) | HOL Guard CVE