{"id":"CVE-2026-13506","title":"In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard","summary":"In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X seri…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-674","CWE-770"],"vendor":"bouncycastle","product":"bc-java","affected":["bc-java < 1.85","bouncy_castle_for_java_lts <= 2.73.11","fips_java_api >= 1.0.0, < 1.0.2.7","fips_java_api >= 2.0.0, < 2.0.2","fips_java_api >= 2.1.0, < 2.1.3"],"patched":["bc-java 1.85","fips_java_api 2.1.3"],"published":"2026-08-03","updated":"2026-08-28","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13506","references":[{"url":"https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84","label":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://github.com/bcgit/bc-java/wiki/CVE-2026-13506","label":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13506"},{"url":"https://github.com/advisories/GHSA-qp49-qgx5-5m26"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13506.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-13506"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510257"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-13506"}],"tags":["nvd","ghsa","maven","csaf","vex","red-hat"],"epss":0.00442,"epssPercentile":0.35762,"ingestedAt":"2026-08-29T16:39:12.748Z","aliases":["GHSA-qp49-qgx5-5m26"],"ecosystem":"maven","slug":"CVE-2026-13506","body":"## Overview\n\nIn Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).\n\n## Affected\n\n- `bc-java < 1.85`\n- `bouncy_castle_for_java_lts <= 2.73.11`\n- `fips_java_api >= 1.0.0, < 1.0.2.7`\n- `fips_java_api >= 2.0.0, < 2.0.2`\n- `fips_java_api >= 2.1.0, < 2.1.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `bc-java 1.85`\n- `fips_java_api 2.1.3`\n\n## Package advisory (CVE-2026-13506)\n\nAffected packages:\n\n- `org.bouncycastle:bcprov-jdk18on < 1.85`\n- `org.bouncycastle:bc-fips < 1.0.2.7`\n- `org.bouncycastle:bc-fips >= 2.0.0, < 2.0.2`\n- `org.bouncycastle:bc-fips >= 2.1.0, < 2.1.3`\n- `org.bouncycastle:bcprov-lts8on < 2.73.12`\n- `org.bouncycastle:bcprov-jdk15to18 < 1.85`\n\nPatched in:\n\n- `org.bouncycastle:bcprov-jdk18on 1.85`\n- `org.bouncycastle:bc-fips 1.0.2.7`\n- `org.bouncycastle:bc-fips 2.0.2`\n- `org.bouncycastle:bc-fips 2.1.3`\n- `org.bouncycastle:bcprov-lts8on 2.73.12`\n- `org.bouncycastle:bcprov-jdk15to18 1.85`\n\nSource: https://github.com/advisories/GHSA-qp49-qgx5-5m26\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat AMQ Broker 7, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat Build of Keycloak, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, Red Hat AMQ Broker 7, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13506.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}