Intel

AIKIDO-2026-647831

bcprov-jdk15on is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionCVE-2026-17508 Published Sep 30, 2026

69

Medium Risk

This Affects:

JAVAbcprov-jdk15on
1.49 - 1.70
Are you affected? Scan for Free

TL;DR

Password-based cryptography entry points accept attacker-controlled KDF cost parameters without complete bounds, so parsing untrusted password-encrypted keys, stores, or parameters spends excessive CPU or memory before authentication succeeds. The fix bounds iteration counts, key length, bcrypt rounds, and the remaining PBMAC1 parameters before derivation or allocation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you parse untrusted password-encrypted keys, stores, or parameters through the Bouncy Castle provider.

Background info

bcprov-jdk15on is vulnerable to Uncontrolled Resource Consumption in versions 1.49 - 1.70.

How to fix this

Migrate the bcprov-jdk15on dependency to bcprov-jdk18on 1.86 or later, or to bcprov-jdk15to18 1.86 or later if you cannot move to Java 8, as the jdk15on coordinates receive no security fixes.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform