PT-2026-33028 · Bouncy Castle · Bc-Java

Xlabai Team

·

Published

2026-04-15

·

Updated

2026-05-19

·

CVE-2025-14813

CVSS v4.0

9.3

Critical

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/RE:M/U:Red
Name of the Vulnerable Software and Affected Versions BC-JAVA versions 1.59 through 1.83
Description The GOSTCTR implementation in the G3413CTRBlockCipher program files is unable to process more than 255 blocks correctly, resulting in the use of a broken or risky cryptographic algorithm.
Recommendations Update to version 1.84.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2025-14813
OPENSUSE-SU-2026:10571-1
RHSA-2026:18054
RHSA-2026:18055

Affected Products

Bc-Java