CVE-2026-97873
Received Received - Intake

Denial of Service in Bouncy Castle Java

Vulnerability report for CVE-2026-97873, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation with an iteration count taken from untrusted input without bounding it, so a small input could dictate an arbitrary amount of work before anything could be verified. The AlgorithmParameters implementations (PKCS12PBE and its object identifier aliases, and PBKDF1) accepted any count from an encoded PKCS12PBEParams or PBEParameter, narrowing a value beyond the int range with intValue(), and every Cipher, Mac and SecretKeyFactory in these families derived with whatever count it was given, including one decoded by another provider's AlgorithmParameters, as when javax.crypto.EncryptedPrivateKeyInfo.getKeySpec() decrypts a PKCS#12 PBE-protected private key with BC. Both the parameter parse and the derivations now reject a negative or over-limit count under the org.bouncycastle.pbe.max_iteration_count property (default 10,000,000) that already bounded PBKDF2 (CVE-2026-17508), and the parse rejects a count beyond the int range rather than narrowing it. This issue also affects Bouncy Castle for Java LTS before 2.73.13.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
org.bouncycastle bouncy_castle 1.86
org.bouncycastle bouncy_castle_lts 2.73.13
bcpg bcpg to 1.86 (exc)
bcpg bcpg to 2.73.13 (exc)
org.bouncycastle bouncy_castle to 1.86 (exc)
org.bouncycastle bouncy_castle to 2.73.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-97873 is a vulnerability in Bouncy Castle for Java before version 1.86 and BC-LTS before 2.73.13. It involves legacy PBES1 and PKCS#12 PBE algorithms where untrusted input dictates the iteration count for password-based key derivation. Attackers can supply small inputs that force excessive computational work, causing delays before authentication. The fix introduces a maximum iteration count limit of 10,000,000 to prevent unbounded CPU usage.

Detection Guidance

Check if your Bouncy Castle Java library version is before 1.86 or BC-LTS before 2.73.13. Use commands like 'mvn dependency:tree' or 'gradle dependencies' to inspect the library version in your project. Monitor CPU usage during decryption operations involving PKCS#12 or PBES1 algorithms for unexpected high delays.

Impact Analysis

This vulnerability can lead to denial-of-service (DoS) attacks by consuming excessive CPU resources. An attacker could send a small malicious input that forces the system to perform an impractical amount of work, such as a 52-byte encrypted key causing up to 20 minutes of CPU time. This disrupts normal operations and degrades system performance.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service (DoS) attacks that exhaust CPU resources during authentication processes. Excessive iteration counts in password-based encryption (PBE) could delay or block access to sensitive data, potentially violating availability requirements under these regulations.

Mitigation Strategies

Upgrade Bouncy Castle to version 1.86 or later, or BC-LTS to 2.73.13 or later. Set the system property 'org.bouncycastle.pbe.max_iteration_count' to a safe default (e.g., 10,000,000) if custom limits are used. Review and update configurations for PKCS#12 key stores and decryptors to enforce iteration count limits.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97873. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart