CVE-2025-9341 Details
Description
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java, org/bouncycastle/crypto/engines/AESNativeCBC.Java. This issue affects Bouncy Castle for Java FIPS: 2.1.0; Bouncy Castle for Java LTS: from 2.73.0 through 2.73.7.
A vulnerability allowing uncontrolled resource consumption has been identified in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS. This issue, present in all API modules, arises from the AESNativeCBC class using a private instance class instead of a private static class. As a result, some garbage collectors failed to reclaim native CBC ciphers no longer in use, potentially leading to an OutOfMemoryError and causing the calling application to fail. This vulnerability affects Bouncy Castle for Java FIPS versions BC-FJA 2.1.0 and BC-LTS 2.73.7.
Users can upgrade to Bouncy Castle for Java FIPS versions BC-FJA 2.1.1 or BC-LTS 2.73.8 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 22, 2025CISA-ADP
Assessed Aug 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%909341 | bcorg | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | bcorg |
Affected Products
| Product | Versions |
|---|---|
| Legion of the Bouncy Castle Inc. Bouncy Castle FIPS | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | bcorg |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | CVE Modified | bcorg |
| Aug 30, 2025 | CVE Modified | bcorg |
| Aug 22, 2025 | New CVE Received | bcorg |
Volerion