Executive brief
Bouncy Castle is a widely-used cryptographic library for Java applications. A vulnerability in its ASN.1 sequence parsing allows attackers to bypass depth-checking protections designed to prevent denial-of-service attacks through deeply nested data structures. An attacker can send malformed ASN.1 data over the network to crash or hang services that depend on Bouncy Castle for cryptographic operations.
Technical details
The vulnerability is an uncontrolled recursion issue (CWE-674) in Bouncy Castle's lazy ASN.1 sequence parsing logic. When processing ASN.1 sequences, the library maintains a nesting-depth guard to prevent stack exhaustion attacks; however, the lazy parsing mechanism can reset this guard, allowing an attacker to exceed safe nesting limits. The vulnerability is remotely exploitable without authentication, affecting multiple Bouncy Castle distributions: standard (before 1.85), LTS (before 2.73.12), and FIPS-certified variants (before 1.0.2.7, 2.0.2, or 2.1.3 depending on series). Successful exploitation results in denial of service through application hang or crash.
Affected products
- Bouncy Castle Bouncy Castle before 1.85
- Bouncy Castle Bouncy Castle LTS before 2.73.12
- Bouncy Castle Bouncy Castle FIPS before 1.0.2.7 (1.0.X), 2.0.2 (2.0.X), 2.1.3 (2.1.X)
Timeline
- 2026-08-03: disclosed
- 2026-09-18: advisory: GitHub Advisory Database review completed