PatchSiren cyber security CVE debrief
CVE-2026-15055 Legion of the Bouncy Castle Inc. CVE debrief
The Bouncy Castle for Java library, prior to version 1.85, contains a vulnerability in its PKCS#8 / PBES2 decryptors that do not properly handle the cost of Key Derivation Functions (KDFs). This issue allows for excessive computational overhead, potentially impacting performance and security. Organizations and developers using Bouncy Castle for Java, especially those handling cryptographic operations in industries such as finance, healthcare, and government, should be aware of this vulnerability. The vulnerability, characterized by a CVSS score of 5.3, indicates a medium severity level. Affected versions include Bouncy Castle for Java before 1.85, Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before specific versions. Further verification is needed to determine the full impact and affected scope due to limited information.
- Vendor
- Legion of the Bouncy Castle Inc.
- Product
- BC-JAVA
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-03
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-08-03
- Advisory updated
- 2026-08-03
Who should care
Organizations and developers using Bouncy Castle for Java, especially those handling cryptographic operations, should be aware of this vulnerability. This includes users of Bouncy Castle for Java in various industries, such as finance, healthcare, and government, where cryptographic security is paramount.
Technical summary
The Bouncy Castle for Java library, prior to version 1.85, contains a vulnerability in its PKCS#8 / PBES2 decryptors. These decryptors do not properly handle the cost of Key Derivation Functions (KDFs), potentially allowing for excessive computational overhead. This issue also affects Bouncy Castle for Java LTS versions before 2.73.12 and Bouncy Castle for Java FIPS (BC-FJA) before specific versions. The vulnerability is characterized by a CVSS score of 5.3, indicating a medium severity level.
Defensive priority
Organizations using Bouncy Castle for Java should review their inventory and apply updates to mitigate potential impacts from unbounded KDF cost in PKCS#8 / PBES2 decryptors.
Recommended defensive actions
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Inventory check: Review and identify all instances of Bouncy Castle for Java in use, including versions before 1.85, Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips
Evidence notes
The CVE record indicates Bouncy Castle for Java before 1.85 is vulnerable to unbounded KDF cost in PKCS#8 / PBES2 decryptors. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before specific versions. However, detailed impact and affected scope require further verification due to limited information.
Official resources
-
CVE-2026-15055 CVE record
CVE.org
-
CVE-2026-15055 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
91579145-5d7b-4cc5-b925-a0262ff19630
-
Source reference
91579145-5d7b-4cc5-b925-a0262ff19630
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T01:16:43.157Z and has not been modified since then.