What is CVE-2026-15055?
In Bouncy Castle for Java, PKCS#8 / PBES2 decryptors accept unbounded KDF cost from input, affecting main versions before 1.85, LTS before 2.73.12, and FIPS (BC-FJA) before 1.0.12, 2.0.12, and 2.1.12. Users should urgently update to the patched releases.
Azərbaycanca: Bouncy Castle for Java kitabxanasında PKCS#8 / PBES2 decryptors komponenti xarici girişdən limitsiz KDF cost qəbul edir. Bu zəiflik versiya 1.85-dən əvvəlki əsas, LTS, və FIPS (BC-FJA) seriyalarına təsir göstərir. İstifadəçilər dərhal müvafiq yamalı versiyalara keçid etməlidir.
Related CVEs
link basis: shared vendor: Bouncy Castle
FAQ2
Which versions of Bouncy Castle for Java are affected by CVE-2026-15055?
This vulnerability affects main versions before 1.85, LTS versions before 2.73.12, and FIPS (BC-FJA) versions before 1.0.12, 2.0.12, and 2.1.12.
What should users do to protect against CVE-2026-15055?
Users should urgently update to the patched versions: main 1.85, LTS 2.73.12, FIPS 1.0.12/2.0.12/2.1.12.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.