Answer in brief
CVE-2025-8916 records a Unknown severity vulnerability in Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation. The current sources do not mark it as known exploited. The current feed maps org.bouncycastle:bcpkix-fips (maven), org.bouncycastle:bcpkix-fips (maven), org.bouncycastle:bcpkix-jdk15on (maven), org.bouncycastle:bcpkix-jdk15to18 (maven) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps org.bouncycastle:bcpkix-fips (maven), org.bouncycastle:bcpkix-fips (maven), org.bouncycastle:bcpkix-jdk15on (maven), org.bouncycastle:bcpkix-jdk15to18 (maven) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| org.bouncycastle:bcpkix-fipsmaven | >=1.0.0 <1.0.8 | 1.0.8 |
| org.bouncycastle:bcpkix-fipsmaven | >=2.0.0 <2.0.8 | 2.0.8 |
| org.bouncycastle:bcpkix-jdk15onmaven | >=1.44 <1.79 | 1.79 |
| org.bouncycastle:bcpkix-jdk15to18maven | >=1.44 <1.79 | 1.79 |
| org.bouncycastle:bcpkix-jdk18onmaven | >=1.44 <1.79 | 1.79 |
Published upstream
Aug 13, 2025
Evidence: source:osv:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:osv:source_dates:source-dates:recordFirst seen by HOL
Sep 10, 2026
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertP... https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.java , https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathRevi... https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.java . This issue affects Bouncy Castle for Java: from BC 1.44 through 1.78, from BCPKIX FIPS 1.0.0 through 1.0.7, from BCPKIX FIPS 2.0.0 through 2.0.7.
Quoted source text, attributed separately from HOL analysis.