CVE-2025-14813 is a cryptographic algorithm vulnerability in Bouncy Castle's BC-JAVA library affecting versions 1.59 through 1.83, wherein the GOSTCTR implementation fails to correctly process data blocks beyond 255 blocks. The vulnerability resides in the G3413CTRBlockCipher program file and represents a broken or risky cryptographic implementation rather than a complete bypass. The vulnerability carries a FAUCET Risk Score of 53.0/100, indicating moderate concern, though a CVSS score has not been assigned. As a cryptographic weakness affecting core encryption functionality, successful exploitation could potentially lead to plaintext recovery or data integrity compromise for applications relying on GOSTCTR encryption for sensitive operations. This vulnerability currently shows no signs of active exploitation in the wild, with no available exploit code in public repositories or known integration into exploit kits. The vulnerability maintains an inactive status on exploitation tracking lists, and the extremely low EPSS score of 0.00004 suggests minimal real-world attack probability at this time. Organizations should prioritize patching to BC-JAVA version 1.84 or later to remediate the cryptographic deficiency.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Legion Of The Bouncy Castle Inc. | BC-JAVA | >= 1.59, < 1.80.2, >= 1.81, < 1.81.1, >= 1.82, < 1.84CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.