CVE-2026-97873

Source
https://cve.org/CVERecord?id=CVE-2026-97873
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97873.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97873
Downstream
Published
2026-10-03T08:04:43Z
Modified
2026-10-05T07:08:37Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Amber CVSS Calculator
Summary
Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider
Details

In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation with an iteration count taken from untrusted input without bounding it, so a small input could dictate an arbitrary amount of work before anything could be verified. The AlgorithmParameters implementations (PKCS12PBE and its object identifier aliases, and PBKDF1) accepted any count from an encoded PKCS12PBEParams or PBEParameter, narrowing a value beyond the int range with intValue(), and every Cipher, Mac and SecretKeyFactory in these families derived with whatever count it was given, including one decoded by another provider's AlgorithmParameters, as when javax.crypto.EncryptedPrivateKeyInfo.getKeySpec() decrypts a PKCS#12 PBE-protected private key with BC. Both the parameter parse and the derivations now reject a negative or over-limit count under the org.bouncycastle.pbe.max_iteration_count property (default 10,000,000) that already bounded PBKDF2 (CVE-2026-17508), and the parse rejects a count beyond the int range rather than narrowing it. This issue also affects Bouncy Castle for Java LTS before 2.73.13.

Database specific
{
    "cna_assigner":  "bcorg",
    "cwe_ids":  [
        "CWE-770"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97873.json"
}
References

Affected packages

Git / github.com/bcgit/bc-java

Affected ranges

Type
GIT
Repo
https://github.com/bcgit/bc-java
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.86"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/bcgit/bc-lts-java
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.73.0"
        },
        {
            "fixed":  "2.73.13"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

Other
r1rv73
r2rv73dot0
r2rv73dot1
r2rv73dot10
r2rv73dot11
r2rv73dot12
r2rv73dot12dot1
r2rv73dot3
r2rv73dot4
r2rv73dot6
r2rv73dot8
r2rv73dot9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97873.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "283110061590036587346140784364806476776",
            "length":  1232
        },
        "id":  "CVE-2026-97873-0a1e3d25",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/bcgit/bc-java/commit/766a31026ac24ed3c6cad8662058ba450c338da1",
        "target":  {
            "file":  "prov/src/main/java/org/bouncycastle/jcajce/provider/symmetric/PBEPBKDF2.java",
            "function":  "engineGenerateSecret"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "138181247408899040249400018688599970935",
                "157076650123742976017600283311648688772",
                "299831574497901735587913555181378186651",
                "119656624553792833336683544475511307167",
                "285360667363707167858519504783424612322"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97873-0d8eac13",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/bcgit/bc-lts-java/commit/43d27611d3b82e54050d1def60b516f8295e485b",
        "target":  {
            "file":  "tls/src/main/java/org/bouncycastle/jsse/provider/BouncyCastleJsseProvider.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "198998642969818417039950766575124474122",
                "176485554327561807626586916754186965744",
                "30122234930542453359703034466236659062",
                "145259701364354400312802743171023262636"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97873-2bd8f355",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/bcgit/bc-lts-java/commit/43d27611d3b82e54050d1def60b516f8295e485b",
        "target":  {
            "file":  "core/src/main/java/org/bouncycastle/crypto/CryptoServicesRegistrar.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "92990237564067571128614587685345852577",
            "length":  4437
        },
        "id":  "CVE-2026-97873-2f9e43f5",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/bcgit/bc-java/commit/766a31026ac24ed3c6cad8662058ba450c338da1",
        "target":  {
            "file":  "prov/src/test/java/org/bouncycastle/jce/provider/test/PBETest.java",
            "function":  "performTest"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "134902664215026488269659596688903720364",
                "321494922550655676952259179890383081274",
                "217078069302867107462901331274123897729",
                "293960044425652652591741690912802394992",
                "259374364529406847406173160088458655021",
                "272849904686859689384915313250555479056",
                "164123936555443215830704205402857699178",
                "146220011011113328214267649677391866772",
                "284772396699507661284043632718803632774",
                "110205475660799871836905570035032413971",
                "56071328906626365426443586358241819754",
                "149856882257116249034692839616809467717",
                "241406231014599686536294786522080062270"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97873-3b933a7f",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/bcgit/bc-java/commit/766a31026ac24ed3c6cad8662058ba450c338da1",
        "target":  {
            "file":  "prov/src/main/java/org/bouncycastle/jcajce/provider/symmetric/PBEPBKDF2.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "107492299239844656455992969154194751546",
                "88031704519188679500783664866555175428",
                "8719723814761448299496542886894605159",
                "203626202713639004218273365189024195254"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97873-3e15219a",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/bcgit/bc-lts-java/commit/43d27611d3b82e54050d1def60b516f8295e485b",
        "target":  {
            "file":  "prov/src/main/java/org/bouncycastle/jce/provider/BouncyCastleProvider.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "15037932978976058678046096832551679440",
            "length":  167
        },
        "id":  "CVE-2026-97873-69554e16",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/bcgit/bc-lts-java/commit/43d27611d3b82e54050d1def60b516f8295e485b",
        "target":  {
            "file":  "prov/src/main/java/org/bouncycastle/jce/provider/BouncyCastleProvider.java",
            "function":  "BouncyCastleProvider"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "327069873105463730607406971638290175233",
            "length":  133
        },
        "id":  "CVE-2026-97873-74c7dc30",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/bcgit/bc-java/commit/766a31026ac24ed3c6cad8662058ba450c338da1",
        "target":  {
            "file":  "prov/src/main/java/org/bouncycastle/jcajce/provider/symmetric/PBEPBKDF2.java",
            "function":  "engineInit"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "142371656489435841291433171748938768211",
                "276114836867604848252227924564245563626",
                "174725713112723821587285552842847152170",
                "296396029911940671522003416275304613740",
                "306388871444103436989662018391338496270",
                "187304475125762585622491255445396488097",
                "161374838074741889965706815960646264073"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97873-be411bea",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/bcgit/bc-java/commit/766a31026ac24ed3c6cad8662058ba450c338da1",
        "target":  {
            "file":  "prov/src/test/java/org/bouncycastle/jce/provider/test/PBETest.java"
        }
    }
]
vanir_signatures_modified
"2026-10-05T07:08:37Z"