Skip to content

CVE‐2026‐14682

David Hook edited this page Aug 3, 2026 · 1 revision

Title: Possible OOM from unbounded up-front allocation on a definite-length read.

Issue affecting: BC before 1.85, BC-LTS before 2.73.12, BC-FJA before bc-fips 1.0.2.7, 2.0.2 and 2.1.3, BC-FJA before bctls-fips 1.0.24.

Fixed versions: BC 1.85, BC-LTS 2.73.12, BC-FJA bc-fips 1.0.2.7, 2.0.2 and 2.1.3, BC-FJA bctls-fips 1.0.24.

Platform affected: Java 8 and later.

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

The fix was introduced in commit 37094e504ef5.

Clone this wiki locally