What is CVE-2026-58063?
CVE-2026-58063 is a vulnerability in Bouncy Castle for Java where BCFKS keystore loading honors an unbounded KDF cost parameter from an untrusted file. This affects versions prior to 1.85, certain LTS releases before 2.73.12, and specific BC-FJA (FIPS) versions, potentially leading to resource exhaustion (DoS). Users should upgrade to the patched versions immediately.
Azərbaycanca: CVE-2026-58063 Bouncy Castle for Java kitabxanasında BCFKS açar saxlayıcısının (keystore) etibarsız fayllardan limitsiz KDF xərc parametrini qəbul etməsi ilə bağlı zəiflikdir. Bu, 1.85-dən əvvəlki əsas versiyalar, müəyyən LTS və BC-FJA (FIPS) versiyalarına təsir edir və resurs tükənməsi (DoS) riski yarada bilər. İstifadəçilər dərhal yamalanmış versiyalara (məsələn, 1.85, 2.73.12, 1.0.2.7) yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Bouncy Castle
FAQ2
What Bouncy Castle functionality is affected by CVE-2026-58063?
This vulnerability affects the BCFKS keystore loading functionality in the Bouncy Castle for Java library. It honors an unbounded KDF cost parameter from an untrusted file.
What is the risk when CVE-2026-58063 is exploited?
Exploitation of this vulnerability can lead to resource exhaustion (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.