{"id":"CVE-2026-13586","title":"In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)","summary":"In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-770","CWE-606"],"vendor":"bouncycastle","product":"bc-java","affected":["bc-java < 1.85","bouncy_castle_for_java_lts <= 2.73.11","fips_java_api >= 1.0.0, < 1.0.2.7","fips_java_api >= 2.0.0, < 2.0.2","fips_java_api >= 2.1.0, < 2.1.3"],"patched":["bc-java 1.85","fips_java_api 2.1.3"],"published":"2026-08-03","updated":"2026-08-28","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13586","references":[{"url":"https://github.com/bcgit/bc-java/commit/75d60dfb4ca72bea6da96234138bc9b1556ef5b0","label":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://github.com/bcgit/bc-java/commit/fa59cc23502f73def89d94374540cc92af647b96","label":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9013586","label":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13586.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-13586"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510252"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-13586"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13586"},{"url":"https://github.com/bcgit/bc-java/wiki/CVE-2026-13586"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00353,"epssPercentile":0.29069,"ingestedAt":"2026-08-29T16:39:12.828Z","scores":{"nvd":7.5,"vendor":6.5},"slug":"CVE-2026-13586","body":"## Overview\n\nIn Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).\n\n## Affected\n\n- `bc-java < 1.85`\n- `bouncy_castle_for_java_lts <= 2.73.11`\n- `fips_java_api >= 1.0.0, < 1.0.2.7`\n- `fips_java_api >= 2.0.0, < 2.0.2`\n- `fips_java_api >= 2.1.0, < 2.1.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `bc-java 1.85`\n- `fips_java_api 2.1.3`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: OpenShift Developer Tools and Services, Red Hat AMQ Broker 7, Red Hat Ansible Automation Platform 2, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat Build of Keycloak, … · no fix planned: OpenShift Developer Tools and Services, Red Hat AMQ Broker 7, Red Hat Ansible Automation Platform 2, Red Hat build of Apache Camel for Spring Boot 4, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13586.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}