---
id: CVE-2026-13506
title: >-
  In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets
  nesting-depth guard
summary: >-
  In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets
  nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before
  2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7
  (1.0.X seri…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-674
  - CWE-770
vendor: bouncycastle
product: bc-java
affected:
  - bc-java < 1.85
  - bouncy_castle_for_java_lts <= 2.73.11
  - 'fips_java_api >= 1.0.0, < 1.0.2.7'
  - 'fips_java_api >= 2.0.0, < 2.0.2'
  - 'fips_java_api >= 2.1.0, < 2.1.3'
patched:
  - bc-java 1.85
  - fips_java_api 2.1.3
published: '2026-08-03'
updated: '2026-08-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13506'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE-2026-13506'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13506'
  - url: 'https://github.com/advisories/GHSA-qp49-qgx5-5m26'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13506.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-13506'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510257'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-13506'
tags:
  - nvd
  - ghsa
  - maven
  - csaf
  - vex
  - red-hat
epss: 0.00442
epssPercentile: 0.35868
ingestedAt: '2026-08-29T16:39:12.748Z'
aliases:
  - GHSA-qp49-qgx5-5m26
ecosystem: maven
---

## Overview

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

## Affected

- `bc-java < 1.85`
- `bouncy_castle_for_java_lts <= 2.73.11`
- `fips_java_api >= 1.0.0, < 1.0.2.7`
- `fips_java_api >= 2.0.0, < 2.0.2`
- `fips_java_api >= 2.1.0, < 2.1.3`

## Remediation

Upgrade past the affected range:

- `bc-java 1.85`
- `fips_java_api 2.1.3`

## Package advisory (CVE-2026-13506)

Affected packages:

- `org.bouncycastle:bcprov-jdk18on < 1.85`
- `org.bouncycastle:bc-fips < 1.0.2.7`
- `org.bouncycastle:bc-fips >= 2.0.0, < 2.0.2`
- `org.bouncycastle:bc-fips >= 2.1.0, < 2.1.3`
- `org.bouncycastle:bcprov-lts8on < 2.73.12`
- `org.bouncycastle:bcprov-jdk15to18 < 1.85`

Patched in:

- `org.bouncycastle:bcprov-jdk18on 1.85`
- `org.bouncycastle:bc-fips 1.0.2.7`
- `org.bouncycastle:bc-fips 2.0.2`
- `org.bouncycastle:bc-fips 2.1.3`
- `org.bouncycastle:bcprov-lts8on 2.73.12`
- `org.bouncycastle:bcprov-jdk15to18 1.85`

Source: https://github.com/advisories/GHSA-qp49-qgx5-5m26

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat AMQ Broker 7, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat Build of Keycloak, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, Red Hat AMQ Broker 7, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13506.json)
