CVE-2026-17508
CVE-2026-17508 — Password-based KDF cost parameters honoured unbounded from untrusted input across the remaining PBE entry points
In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an arbitrary amount of work before any password or integrity check could reject it. The affected paths are the RFC 9579 PBMAC1 MAC calculator builders, which took the PBKDF2 iteration count and derived-key length straight out of PBMAC1Params (JcePBMac1CalculatorBuilder, and PKCS12PBEUtils.createPBMac1Calculator reached from PKCS12PfxPdu.isMacValid); the scrypt parallelization parameter p in the PKCS#8 and PKCS#12 cost guards, which bounded only the cost parameter N and the block size r even though the scratch buffer scales with r times p, so the configured memory ceiling could be evaded entirely; the raw JCA PBKDF2 provider…
Published Updated Sources: cvelistV5, bcorg
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
0%
chance of exploitation in 30 days
CVSS base
5.3
MEDIUM
CISA SSVC assessment
Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.
Exploitation
None
none · proof-of-concept · active
Automatable
No
can an attacker script all four kill-chain steps
Technical impact
Partial
partial · total control of the vulnerable component
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (3)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 5.3 | CVSS 4.0 | MEDIUM | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-770
Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.
- T1498.001Network Denial of Service: Direct Network Flood
- T1499Endpoint Denial of Service
- T1499.003Endpoint Denial of Service: Application Exhaustion Flood
References
7 on the record
- github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9017508
vendor-advisory
- github.com/bcgit/bc-java/commit/882fdab53f6c4c150a5d6a4e6ef1fc05d382385a
patch
- github.com/bcgit/bc-java/commit/442393bf187c914b1e66fbed4fab532a1fe06c6a
patch
- github.com/bcgit/bc-java/commit/20ed9e203caec91d25cd386ceb6d364e9b068f67
patch
- github.com/bcgit/bc-java/commit/766a31026ac24ed3c6cad8662058ba450c338da1
patch
- github.com/bcgit/bc-java/commit/e72bc0681ff4227fced912ef7394daf7b7d57bb3
patch
- github.com/bcgit/bc-java/commit/480d878aa6f7dc8b20403064f304bbe0decbbb1a
patch
Elsewhere on this site
- legion of the bouncy castleevery CVE for this vendor
- CWE-770other pages naming this weakness
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.