CVE-2025-12194
BaseFortify
Publication date: 2025-10-24
Last updated on: 2025-10-27
Assigner: bcorg
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| legion_of_the_bouncy_castle_inc | bouncy_castle_for_java_fips | 2.1.1 |
| legion_of_the_bouncy_castle_inc | bouncy_castle_for_java_lts | 2.73.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Uncontrolled Resource Consumption issue in the Legion of the Bouncy Castle Inc. Bouncy Castle for Java libraries (FIPS and LTS versions). It allows excessive allocation of resources, which means the affected software can consume more memory or processing power than intended due to improper handling in certain cryptographic API modules.
How can this vulnerability impact me? :
The vulnerability can lead to excessive resource consumption, potentially causing performance degradation, denial of service, or system instability in applications using the affected Bouncy Castle Java libraries. This can disrupt normal operations and affect availability.