PatchSiren cyber security CVE debrief
CVE-2026-58063 Legion of the Bouncy Castle Inc. CVE debrief
The CVE record for CVE-2026-58063 was published on 2026-08-03T03:16:45.773Z and has not been modified since then. The NVD entry is currently empty. This CVE is related to Bouncy Castle for Java before 1.85, Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before specific versions. The vulnerability involves BCFKS keystore load honouring unbounded KDF cost from untrusted files, potentially leading to performance degradation or denial-of-service conditions. Organizations should verify Bouncy Castle for Java versions in use and consider upgrading to a secure version. Defenders should also review KDF cost settings and monitor for suspicious activity related to keystore loads.
- Vendor
- Legion of the Bouncy Castle Inc.
- Product
- BC-JAVA
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-03
- Original CVE updated
- 2026-09-02
- Advisory published
- 2026-08-03
- Advisory updated
- 2026-09-02
Who should care
Organizations using Bouncy Castle for Java library versions before 1.85, as well as those using Bouncy Castle for Java LTS before 2.73.12 and Bouncy Castle for Java FIPS (BC-FJA) before specific versions, should be aware of this vulnerability and take necessary actions to upgrade or mitigate the risk. This includes security teams, vulnerability management teams, and operators of systems that utilize Bouncy Castle for Java. Additionally, platform administrators and security personnel responsible for monitoring and incident response should be informed about the potential impacts of this vulnerability.
Technical summary
The Bouncy Castle for Java library before version 1.85 has a vulnerability in the BCFKS keystore load functionality, which honours unbounded KDF cost from untrusted files. This issue also affects Bouncy Castle for Java LTS before 2.73.12 and Bouncy Castle for Java FIPS (BC-FJA) before specific versions. The vulnerability has a CVSS score of 5.3, indicating a medium severity level. The unbounded KDF cost issue could potentially lead to performance degradation or denial-of-service conditions. Organizations using affected versions of Bouncy Castle for Java should prioritize upgrading to a secure version.
Defensive priority
Medium priority given the CVSS score of 5.3 and the potential for unbounded KDF cost issues.
Recommended defensive actions
- Verify Bouncy Castle for Java version and upgrade to 1.85 or later if necessary.
- Review and adjust KDF cost settings for BCFKS keystore loads.
- Monitor for any suspicious activity related to keystore loads.
- Perform a thorough review of the Bouncy Castle for Java library usage within the organization.
- Check for any exposed systems that require compensating controls while remediation is scheduled.
- Track exceptions and retest remediated assets.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The evidence for CVE-2026-58063 is limited; primary official records indicate Bouncy Castle for Java before 1.85 has an issue with BCFKS keystore load honouring unbounded KDF cost from untrusted files. Defenders should verify Bouncy Castle for Java versions in use, review KDF cost settings, and monitor for suspicious activity related to keystore loads. Additional verification tasks may be necessary based on specific deployment contexts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58063 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58063
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58063 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58063
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06
91579145-5d7b-4cc5-b925-a0262ff19630
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/wiki/CVE-2026-58063
91579145-5d7b-4cc5-b925-a0262ff19630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.