In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
Update Legion of the Bouncy Castle Inc./BC-FJA to 1.0.2.7; Legion of the Bouncy Castle Inc./BC-FJA to 1.0.24; Legion of the Bouncy Castle Inc./BC-JAVA to 1.85; Legion of the Bouncy Castle Inc./BC-LTS-JAVA to 2.73.12 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanPossible OOM from unbounded up-front allocation on a definite-length read affects Legion of the Bouncy Castle Inc./BC-FJA (generic), Legion of the Bouncy Castle Inc./BC-FJA (generic), Legion of the Bouncy Castle Inc./BC-JAVA (generic), Legion of the Bouncy Castle Inc./BC-LTS-JAVA (generic). Severity is high. In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
Update Legion of the Bouncy Castle Inc./BC-FJA to 1.0.2.7; Legion of the Bouncy Castle Inc./BC-FJA to 1.0.24; Legion of the Bouncy Castle Inc./BC-JAVA to 1.85; Legion of the Bouncy Castle Inc./BC-LTS-JAVA to 2.73.12 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanPossible OOM from unbounded up-front allocation on a definite-length read affects Legion of the Bouncy Castle Inc./BC-FJA (generic), Legion of the Bouncy Castle Inc./BC-FJA (generic), Legion of the Bouncy Castle Inc./BC-JAVA (generic), Legion of the Bouncy Castle Inc./BC-LTS-JAVA (generic). Severity is high. In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Legion of the Bouncy Castle Inc./BC-FJAgeneric |
|---|
| >=1.0.0 <1.0.2.7 || >=2.0.0 <2.0.2 || >=2.1.0 <2.1.3 |
| 1.0.2.7, 2.0.2, 2.1.3 |
| Legion of the Bouncy Castle Inc./BC-FJAgeneric | >=1.0.0 <1.0.24 | 1.0.24 |
|---|
| Legion of the Bouncy Castle Inc./BC-JAVAgeneric | >=0 <1.85 | 1.85 |
|---|
| Legion of the Bouncy Castle Inc./BC-LTS-JAVAgeneric | >=2.73.0 <2.73.12 | 2.73.12 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Legion of the Bouncy Castle Inc./BC-FJAgeneric |
|---|
| >=1.0.0 <1.0.2.7 || >=2.0.0 <2.0.2 || >=2.1.0 <2.1.3 |
| 1.0.2.7, 2.0.2, 2.1.3 |
| Legion of the Bouncy Castle Inc./BC-FJAgeneric | >=1.0.0 <1.0.24 | 1.0.24 |
|---|
| Legion of the Bouncy Castle Inc./BC-JAVAgeneric | >=0 <1.85 | 1.85 |
|---|
| Legion of the Bouncy Castle Inc./BC-LTS-JAVAgeneric | >=2.73.0 <2.73.12 | 2.73.12 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard