CVE-2025-8885: Possible DOS in processing specially formed ASN.1 Object Identifiers
A resource allocation vulnerability exists in Bouncy Castle for Java (by Legion of the Bouncy Castle Inc.) that affects all API modules. The vulnerability allows attackers to cause excessive memory allocation through unbounded resource consumption, potentially leading to denial of service. The issue is located in the ASN1ObjectIdentifier.java file in the core module.
This issue affects Bouncy Castle for Java: from BC 1.0 through 1.77, from BC-FJA 1.0.0 through 2.0.0.
Other sources
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files
— IBM
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcprov, bc-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java.
This issue affects Bouncy Castle for Java: from BC 1.0 through 1.77, from BC-FJA 1.0.0 through 1.0.2.5, from BC-FJA 2.0.0 through 2.0.0.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8885?
CVE-2025-8885 has a moderate severity rating due to the potential for excessive resource allocation.
How do I fix CVE-2025-8885?
To fix CVE-2025-8885, upgrade to Bouncy Castle for Java version 1.78 or later.
What types of applications are affected by CVE-2025-8885?
CVE-2025-8885 affects the Bouncy Castle for Java and Bouncy Castle for Java-FJA libraries.
What is the main consequence of CVE-2025-8885?
The main consequence of CVE-2025-8885 is that it allows an attacker to cause denial of service through resource exhaustion.
Is CVE-2025-8885 present in all versions of Bouncy Castle for Java?
CVE-2025-8885 is present in Bouncy Castle for Java versions from 1.0 up to 1.77.