{"id":"CVE-2026-14682","title":"In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read","summary":"In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-789","CWE-770"],"vendor":"bouncycastle","product":"bc-java","affected":["bc-java < 1.85","bctls-fips < 1.0.24","bouncy_castle_for_java_lts <= 2.73.11","fips_java_api >= 1.0.0, < 1.0.2.7","fips_java_api >= 2.0.0, < 2.0.2","fips_java_api >= 2.1.0, < 2.1.3"],"patched":["bc-java 1.85","bctls-fips 1.0.24","fips_java_api 2.1.3"],"published":"2026-08-03","updated":"2026-08-28","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14682","references":[{"url":"https://github.com/bcgit/bc-java/commit/37094e504ef50cf9ce4e0fb9e5105d495ff5c2d2","label":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9014682","label":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14682.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-14682"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510258"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-14682"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14682"},{"url":"https://github.com/bcgit/bc-java/wiki/CVE-2026-14682"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.0031,"epssPercentile":0.24001,"ingestedAt":"2026-08-29T16:39:12.870Z","slug":"CVE-2026-14682","body":"## Overview\n\nIn Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.\n\n## Affected\n\n- `bc-java < 1.85`\n- `bctls-fips < 1.0.24`\n- `bouncy_castle_for_java_lts <= 2.73.11`\n- `fips_java_api >= 1.0.0, < 1.0.2.7`\n- `fips_java_api >= 2.0.0, < 2.0.2`\n- `fips_java_api >= 2.1.0, < 2.1.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `bc-java 1.85`\n- `bctls-fips 1.0.24`\n- `fips_java_api 2.1.3`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Single Sign-On 7 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14682.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}