Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12852

Опубликовано: 03 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

A flaw was found in Bouncy Castle for Java. A remote attacker could exploit this by providing a specially crafted message to the MLS wire decoder. The decoder allocates an attacker-declared opaque length without first performing a bounds check. This can lead to excessive memory allocation, resulting in a Denial of Service (DoS) for the application.

Отчет

This vulnerability targets the Messaging Layer Security (MLS) module, which in Bouncy Castle is packaged as bcmls. No Red Hat products are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4bcpkix-jdk18onNot affected
Cryostat 4bcprov-jdk18onNot affected
Cryostat 4bcutil-jdk18onNot affected
OpenShift Developer Tools and ServicesjenkinsNot affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsNot affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-agent-base-rhel8Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-agent-base-rhel9Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Not affected
Red Hat AMQ Broker 7bcpkix-jdk18onNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1284
https://bugzilla.redhat.com/show_bug.cgi?id=2510255bouncycastle: Bouncy Castle for Java: Denial of Service via MLS wire decoder

EPSS

Процентиль: 18%
0.00263
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
16 дней назад

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

nvd
16 дней назад

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

debian
16 дней назад

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates atta ...

github
16 дней назад

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

suse-cvrf
13 дней назад

Security update for bouncycastle

EPSS

Процентиль: 18%
0.00263
Низкий

7.5 High

CVSS3