CRITICALMaven →
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
Affected packages
- org.bouncycastle:bcprov-debug-jdk14— ≥ 1.59
- org.bouncycastle:bcprov-debug-jdk15to18— ≥ 1.59
- org.bouncycastle:bcprov-debug-jdk18on— ≥ 1.59
- org.bouncycastle:bcprov-ext-debug-jdk14— ≥ 1.59
- org.bouncycastle:bcprov-ext-debug-jdk15to18— ≥ 1.59
- org.bouncycastle:bcprov-ext-debug-jdk18on— ≥ 1.59
- org.bouncycastle:bcprov-ext-jdk14— ≥ 1.59
- org.bouncycastle:bcprov-ext-jdk15to18— ≥ 1.59
- org.bouncycastle:bcprov-ext-jdk18on— ≥ 1.59
- org.bouncycastle:bcprov-jdk14— ≥ 1.59
- org.bouncycastle:bcprov-jdk15to18— ≥ 1.59
- org.bouncycastle:bcprov-jdk18on— 1.59 → 1.80.2
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2025-14813
- https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f
- https://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813
- https://github.com/bcgit/bc-java
- https://bugzilla.redhat.com/show_bug.cgi?id=2458640
- https://access.redhat.com/security/cve/CVE-2025-14813
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/errata/RHSA-2026:21772
- https://access.redhat.com/errata/RHSA-2026:18059
- https://access.redhat.com/errata/RHSA-2026:18055
- https://access.redhat.com/errata/RHSA-2026:18054
- https://access.redhat.com/errata/RHSA-2026:17668
- https://access.redhat.com/errata/RHSA-2026:14276
- https://access.redhat.com/errata/RHSA-2026:14272
- https://access.redhat.com/errata/RHSA-2026:13631
- https://access.redhat.com/errata/RHSA-2026:11721
- https://access.redhat.com/errata/RHSA-2026:11720
Structured record: https://osv.dev/vulnerability/GHSA-574f-3g2m-x479
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta