---
id: CVE-2026-14682
title: >-
  In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front
  allocation on a definite-length read
summary: >-
  In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front
  allocation on a definite-length read. This issue also affects Bouncy Castle
  for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before
  bc-fips …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-789
  - CWE-770
vendor: bouncycastle
product: bc-java
affected:
  - bc-java < 1.85
  - bctls-fips < 1.0.24
  - bouncy_castle_for_java_lts <= 2.73.11
  - 'fips_java_api >= 1.0.0, < 1.0.2.7'
  - 'fips_java_api >= 2.0.0, < 2.0.2'
  - 'fips_java_api >= 2.1.0, < 2.1.3'
patched:
  - bc-java 1.85
  - bctls-fips 1.0.24
  - fips_java_api 2.1.3
published: '2026-08-03'
updated: '2026-08-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14682'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/37094e504ef50cf9ce4e0fb9e5105d495ff5c2d2
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9014682'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14682.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-14682'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510258'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-14682'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14682'
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE-2026-14682'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.0031
epssPercentile: 0.24086
ingestedAt: '2026-08-29T16:39:12.870Z'
---

## Overview

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.

## Affected

- `bc-java < 1.85`
- `bctls-fips < 1.0.24`
- `bouncy_castle_for_java_lts <= 2.73.11`
- `fips_java_api >= 1.0.0, < 1.0.2.7`
- `fips_java_api >= 2.0.0, < 2.0.2`
- `fips_java_api >= 2.1.0, < 2.1.3`

## Remediation

Upgrade past the affected range:

- `bc-java 1.85`
- `bctls-fips 1.0.24`
- `fips_java_api 2.1.3`

## Vendor advisories

- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, Red Hat AMQ Broker 7, Red Hat Ansible Automation Platform 2, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat Build of Keycloak, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, OpenShift Developer Tools and Services, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14682.json)
