PatchSiren cyber security CVE debrief
CVE-2026-97873 Legion of the Bouncy Castle Inc. CVE debrief
This CVE debrief is based on the supplied source corpus. The CVE record was published on 2026-10-03T09:17:06.280Z and has not been modified since then. The vulnerability in Bouncy Castle for Java, prior to version 1.86, and Bouncy Castle for Java LTS, prior to version 2.73.13, allows for unbounded iteration counts in password-based key derivation, potentially leading to denial-of-service attacks. Defenders should assess exposure and prioritize remediation to prevent potential impacts on Java applications using Bouncy Castle.
- Vendor
- Legion of the Bouncy Castle Inc.
- Product
- BC-JAVA
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for Java applications using Bouncy Castle should assess exposure and prioritize remediation to prevent potential denial-of-service attacks. This includes verifying and remediating vulnerable Bouncy Castle for Java versions, reviewing and adjusting password-based key derivation configurations, and implementing compensating controls for exposed systems. Security teams and vulnerability management teams should also review monitoring and
Why it matters
Defenders should prioritize verifying and remediating Bouncy Castle for Java versions to prevent potential denial-of-service attacks. Evidence is limited to official CVE and NVD records, and two GitHub references.
- Potential denial-of-service attacks due to unbounded iteration counts
- Need to verify and remediate vulnerable Bouncy Castle for Java versions
- Possible impact on Java applications using Bouncy Castle for password-based key derivation
Technical summary
The Bouncy Castle for Java library, prior to version 1.86, and Bouncy Castle for Java LTS, prior to version 2.73.13, contain a vulnerability in the raw JCA provider's legacy PBES1 and PKCS#12 PBE families. The vulnerability allows for unbounded iteration counts in password-based key derivation, potentially leading to denial-of-service attacks. This issue affects Java applications using Bouncy Castle for password-based key derivation. The AlgorithmParameters implementations accepted any count from an encoded PKCS12PBEParams or PBEParameter, narrowing a value beyond the int range with intValue(), and every Cipher, Mac and SecretKeyFactory in these families derived with whatever count it was given.
Defensive priority
Defenders should prioritize verifying and remediating Bouncy Castle for Java versions before 1.86, and Bouncy Castle for Java LTS before 2.73.13, to prevent potential denial-of-service attacks.
Recommended defensive actions
- Verify Bouncy Castle for Java versions and upgrade to 1.86 or later
- Verify Bouncy Castle for Java LTS versions and upgrade to 2.73.13 or later
- Review and adjust password-based key derivation configurations
- Perform vulnerability scanning to identify exposed systems
- Implement compensating controls for exposed systems
- Review monitoring and detection configurations for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Bouncy Castle for Java, which could allow for denial-of-service attacks due to unbounded iteration counts in password-based key derivation. Evidence is limited to official CVE and NVD records, and two GitHub references.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97873 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97873
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97873 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97873
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/commit/766a31026ac24ed3c6cad8662058ba450c338da1
91579145-5d7b-4cc5-b925-a0262ff19630
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9097873
91579145-5d7b-4cc5-b925-a0262ff19630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.