---
id: CVE-2025-14813
title: >-
  : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of
  the Bouncy Castle Inc
summary: >-
  : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of
  the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).

   This vulnerability is associated with program files G3413CTRBlockCipher.



  This issue affects B…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-327
  - CWE-323
vendor: Legion of the Bouncy Castle Inc.
product: bcprov
affected:
  - bcprov >= 1.59 < 1.80.2
  - bcprov >= 1.81 < 1.81.1
  - bcprov >= 1.82 < 1.84
patched:
  - jboss_eap_7_4_els_for_rhel_7_server
  - jboss_eap_8_1_for_rhel 8
  - jboss_eap_8_1_for_rhel 9
  - openshift_developer_tools_and_services 4.12
  - openshift_developer_tools_and_services 4.13
  - openshift_developer_tools_and_services 4.14
  - openshift_developer_tools_and_services 4.15
  - openshift_developer_tools_and_services 4.16
  - openshift_developer_tools_and_services 4.17
  - openshift_developer_tools_and_services 4.18
  - openshift_developer_tools_and_services 4.19
  - openshift_developer_tools_and_services 4.20
  - openshift_developer_tools_and_services 4.21
  - openshift_developer_tools_and_services 4.22
  - amq_broker 7.12.7
  - amq_broker 7.13.5
  - build_of_apache_camel_4_14_for_quarkus 3.27
  - jboss_enterprise_application_platform 7.4.25
  - jboss_enterprise_application_platform 8.1
  - openshift_ai 2.25
  - openshift_dev_spaces 3.28
  - build_of_apache_camel_4_18_1_for_spring_boot 3.5.14
  - build_of_quarkus 3.20.6.SP1
  - build_of_quarkus 3.27.3.SP1
published: '2026-04-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:17:06.953'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14813'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://access.redhat.com/errata/RHSA-2026:11720'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11721'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13631'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14272'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14276'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17668'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:18054'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:18055'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:18059'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21772'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24977'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:53644'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:53645'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:53646'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60239'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60246'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60247'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60248'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60249'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60250'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60251'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60252'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60254'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60256'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60259'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:66488'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2025-14813'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2458640'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:53806'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-14813'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14813'
  - url: 'https://github.com/advisories/GHSA-574f-3g2m-x479'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - ghsa
  - maven
epss: 0.0032
epssPercentile: 0.22198
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-04-15T13:19:43.094033Z'
scores:
  nvd: 7.5
  cna: 9.3
  vendor: 7.5
  ghsa: 7.5
ingestedAt: '2026-07-16T12:53:55.903Z'
aliases:
  - GHSA-574f-3g2m-x479
ecosystem: maven
---

## Overview

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).

 This vulnerability is associated with program files G3413CTRBlockCipher.



This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:53644** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53644)
- **RHSA-2026:18054** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 8 · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18054)
- **RHSA-2026:18055** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 9 · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18055)
- **RHSA-2026:60247** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.12 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60247)
- **RHSA-2026:60249** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.13 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60249)
- **RHSA-2026:60248** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.14 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60248)
- **RHSA-2026:60239** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.15 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60239)
- **RHSA-2026:60251** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.16 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60251)
- **RHSA-2026:60246** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.17 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60246)
- **RHSA-2026:60250** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.18 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60250)
- **RHSA-2026:60252** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.19 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60252)
- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, Red Hat AMQ Clients, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat Enterprise Linux 8, … · no fix planned: Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat Enterprise Linux 8, Red Hat Fuse 7, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json)
- **RHSA-2026:53645** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 8 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53645)
- **RHSA-2026:53646** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 9 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53646)

## Package advisory (CVE-2025-14813)

Affected packages:

- `org.bouncycastle:bcprov-jdk14 >= 1.59, <= 1.80.1`
- `org.bouncycastle:bcprov-jdk15to18 >= 1.59, <= 1.80.1`
- `org.bouncycastle:bcprov-jdk18on >= 1.59, <= 1.80.1`
- `org.bouncycastle:bcprov-debug-jdk14 >= 1.59, <= 1.80.1`
- `org.bouncycastle:bcprov-debug-jdk15to18 >= 1.59, <= 1.80.1`
- `org.bouncycastle:bcprov-debug-jdk18on >= 1.59, <= 1.80.1`
- `org.bouncycastle:bcprov-ext-jdk14 >= 1.59, <= 1.78.1`
- `org.bouncycastle:bcprov-ext-jdk15to18 >= 1.59, <= 1.78.1`
- `org.bouncycastle:bcprov-ext-jdk18on >= 1.59, <= 1.78.1`
- `org.bouncycastle:bcprov-ext-debug-jdk14 >= 1.59, <= 1.74`
- `org.bouncycastle:bcprov-ext-debug-jdk15to18 >= 1.59, <= 1.77`
- `org.bouncycastle:bcprov-ext-debug-jdk18on >= 1.59, <= 1.77`
- `org.bouncycastle:bcprov-jdk14 = 1.81.0`
- `org.bouncycastle:bcprov-jdk15to18 = 1.81.0`
- `org.bouncycastle:bcprov-jdk18on = 1.81.0`
- `org.bouncycastle:bcprov-debug-jdk14 = 1.81.0`
- `org.bouncycastle:bcprov-debug-jdk15to18 = 1.81.0`
- `org.bouncycastle:bcprov-debug-jdk18on = 1.81.0`
- `org.bouncycastle:bcprov-jdk14 >= 1.82, <= 1.83`
- `org.bouncycastle:bcprov-jdk15to18 >= 1.82, <= 1.83`
- `org.bouncycastle:bcprov-jdk18on >= 1.82, <= 1.83`
- `org.bouncycastle:bcprov-debug-jdk14 >= 1.82, <= 1.83`
- `org.bouncycastle:bcprov-debug-jdk15to18 >= 1.82, <= 1.83`
- `org.bouncycastle:bcprov-debug-jdk18on >= 1.82, <= 1.83`
- `org.bouncycastle:bcprov-debug-jdk15on <= 1.7.0`
- `org.bouncycastle:bcprov-jdk15on <= 1.7.0`

Patched in:

- `org.bouncycastle:bcprov-jdk18on 1.80.2`
- `org.bouncycastle:bcprov-jdk18on 1.81.1`
- `org.bouncycastle:bcprov-jdk14 1.84`
- `org.bouncycastle:bcprov-jdk15to18 1.84`
- `org.bouncycastle:bcprov-jdk18on 1.84`
- `org.bouncycastle:bcprov-debug-jdk14 1.84`
- `org.bouncycastle:bcprov-debug-jdk15to18 1.84`
- `org.bouncycastle:bcprov-debug-jdk18on 1.84`

Source: https://github.com/advisories/GHSA-574f-3g2m-x479
