PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97873 Legion of the Bouncy Castle Inc. CVE debrief

This CVE debrief is based on the supplied source corpus. The CVE record was published on 2026-10-03T09:17:06.280Z and has not been modified since then. The vulnerability in Bouncy Castle for Java, prior to version 1.86, and Bouncy Castle for Java LTS, prior to version 2.73.13, allows for unbounded iteration counts in password-based key derivation, potentially leading to denial-of-service attacks. Defenders should assess exposure and prioritize remediation to prevent potential impacts on Java applications using Bouncy Castle.

Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for Java applications using Bouncy Castle should assess exposure and prioritize remediation to prevent potential denial-of-service attacks. This includes verifying and remediating vulnerable Bouncy Castle for Java versions, reviewing and adjusting password-based key derivation configurations, and implementing compensating controls for exposed systems. Security teams and vulnerability management teams should also review monitoring and

Why it matters

Defenders should prioritize verifying and remediating Bouncy Castle for Java versions to prevent potential denial-of-service attacks. Evidence is limited to official CVE and NVD records, and two GitHub references.

  • Potential denial-of-service attacks due to unbounded iteration counts
  • Need to verify and remediate vulnerable Bouncy Castle for Java versions
  • Possible impact on Java applications using Bouncy Castle for password-based key derivation

Technical summary

The Bouncy Castle for Java library, prior to version 1.86, and Bouncy Castle for Java LTS, prior to version 2.73.13, contain a vulnerability in the raw JCA provider's legacy PBES1 and PKCS#12 PBE families. The vulnerability allows for unbounded iteration counts in password-based key derivation, potentially leading to denial-of-service attacks. This issue affects Java applications using Bouncy Castle for password-based key derivation. The AlgorithmParameters implementations accepted any count from an encoded PKCS12PBEParams or PBEParameter, narrowing a value beyond the int range with intValue(), and every Cipher, Mac and SecretKeyFactory in these families derived with whatever count it was given.

Defensive priority

Defenders should prioritize verifying and remediating Bouncy Castle for Java versions before 1.86, and Bouncy Castle for Java LTS before 2.73.13, to prevent potential denial-of-service attacks.

Recommended defensive actions

  • Verify Bouncy Castle for Java versions and upgrade to 1.86 or later
  • Verify Bouncy Castle for Java LTS versions and upgrade to 2.73.13 or later
  • Review and adjust password-based key derivation configurations
  • Perform vulnerability scanning to identify exposed systems
  • Implement compensating controls for exposed systems
  • Review monitoring and detection configurations for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Bouncy Castle for Java, which could allow for denial-of-service attacks due to unbounded iteration counts in password-based key derivation. Evidence is limited to official CVE and NVD records, and two GitHub references.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97873 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97873

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97873 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97873

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/commit/766a31026ac24ed3c6cad8662058ba450c338da1

    91579145-5d7b-4cc5-b925-a0262ff19630

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9097873

    91579145-5d7b-4cc5-b925-a0262ff19630

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.