← Back

CVE-2026-58063

nvd nist
Published: Aug 3, 2026Modified: Sep 2, 2026

JSON object

Loading...
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:AmberShow less
Source: 91579145-5d7b-4cc5-b925-a0262ff19630 (Secondary)

Description

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Affected (5)

3 products
Bc Java
Bouncy Castle For Java Lts
Fips Java Api
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.85
Up to 2.73.11
Bouncycastle
From 1.0.0 to 1.0.2.7
From 2.0.0 to 2.0.2
From 2.1.0 to 2.1.3

References (2)

Source: 91579145-5d7b-4cc5-b925-a0262ff19630
Third Party AdvisoryPatch

Timeline

No history available yet.