CVE-2025-14813
Received
Received - Intake
Broken Cryptographic Algorithm in BC-JAVA GOSTCTR Causes Data Integrity Risk
Publication date: 2026-04-15
Last updated on: 2026-05-19
Assigner: bcorg
Description
Description
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).
This vulnerability is associated with program files G3413CTRBlockCipher.
This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| legion_of_the_bouncy_castle_inc | bc-java | From 1.59 (inc) to 1.84 (exc) |
| legion_of_the_bouncy_castle_inc | bc-java | to 1.84 (exc) |
| legion_of_the_bouncy_castle_inc | bc-java | 1.84 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-327 | The product uses a broken or risky cryptographic algorithm or protocol. |