CVE-2025-12194 describes an Uncontrolled Resource Consumption vulnerability (CWE-400) affecting Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS (versions 2.1.0 through 2.1.1) and Bouncy Castle for Java LTS (versions 2.73.0 through 2.73.7). This flaw, specifically "Excessive Allocation," is present in numerous native cryptographic engine and digest files. The vulnerability carries a CVSS 4.0 score of 5.9 (Medium), indicating a local attack vector with low attack complexity, requiring no privileges or user interaction. The primary impact is high availability degradation, as an attacker could exhaust system resources. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Legion Of The Bouncy Castle Inc. | Bouncy Castle For Java FIPS | >= 2.1.0, <= 2.1.1CNA affecteddefault unaffected | |
| Legion Of The Bouncy Castle Inc. | Bouncy Castle For Java LTS | >= 2.73.0, <= 2.73.7CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:C/RE:M/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.