CVE-2025-8885: Possible DOS in processing specially formed ASN.1 Object Identifiers

Published Aug 12, 2025
·
Updated

A resource allocation vulnerability exists in Bouncy Castle for Java (by Legion of the Bouncy Castle Inc.) that affects all API modules. The vulnerability allows attackers to cause excessive memory allocation through unbounded resource consumption, potentially leading to denial of service. The issue is located in the ASN1ObjectIdentifier.java file in the core module.

This issue affects Bouncy Castle for Java: from BC 1.0 through 1.77, from BC-FJA 1.0.0 through 2.0.0.

Other sources

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files

IBM

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcprov, bc-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java.

This issue affects Bouncy Castle for Java: from BC 1.0 through 1.77, from BC-FJA 1.0.0 through 1.0.2.5, from BC-FJA 2.0.0 through 2.0.0.

NVD

Affected Software

9 affected componentsFixes available
Bouncy Castle Bouncy Castle for Java>=1.0<=1.77
Bouncy Castle Bouncy Castle for Java-FJA>=1.0.0<=2.0.0
maven/org.bouncycastle:bc-fips>=1.0.0<=2.0.0
2.1.0
maven/org.bouncycastle:bctls-jdk18on>=1.0<1.78
1.78
maven/org.bouncycastle:bctls-jdk15to18>=1.0<1.78
1.78
maven/org.bouncycastle:bctls-jdk14>=1.0<1.78
1.78
maven/org.bouncycastle:bcprov-jdk18on>=1.0<1.78
1.78
maven/org.bouncycastle:bcprov-jdk15to18>=1.0<1.78
1.78
maven/org.bouncycastle:bcprov-jdk14>=1.0<1.78
1.78

Event History

Aug 12, 2025
CVE Published
via MITRE·09:13 AM
Data Sourced
via MITRE·09:13 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:30 PM
Data Sourced
via GitHub·12:30 PM
DescriptionWeaknessAffected Software
Nov 3, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Dec 25, 57917
Event
via FIRST·11:34 AM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-8885?

CVE-2025-8885 has a moderate severity rating due to the potential for excessive resource allocation.

2

How do I fix CVE-2025-8885?

To fix CVE-2025-8885, upgrade to Bouncy Castle for Java version 1.78 or later.

3

What types of applications are affected by CVE-2025-8885?

CVE-2025-8885 affects the Bouncy Castle for Java and Bouncy Castle for Java-FJA libraries.

4

What is the main consequence of CVE-2025-8885?

The main consequence of CVE-2025-8885 is that it allows an attacker to cause denial of service through resource exhaustion.

5

Is CVE-2025-8885 present in all versions of Bouncy Castle for Java?

CVE-2025-8885 is present in Bouncy Castle for Java versions from 1.0 up to 1.77.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203