Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-14813

28
FAUCET Score

CVE-2025-14813 is a cryptographic algorithm vulnerability in Bouncy Castle's BC-JAVA library affecting versions 1.59 through 1.83, wherein the GOSTCTR implementation fails to correctly process data blocks beyond 255 blocks. The vulnerability resides in the G3413CTRBlockCipher program file and represents a broken or risky cryptographic implementation rather than a complete bypass. The vulnerability carries a FAUCET Risk Score of 53.0/100, indicating moderate concern, though a CVSS score has not been assigned. As a cryptographic weakness affecting core encryption functionality, successful exploitation could potentially lead to plaintext recovery or data integrity compromise for applications relying on GOSTCTR encryption for sensitive operations. This vulnerability currently shows no signs of active exploitation in the wild, with no available exploit code in public repositories or known integration into exploit kits. The vulnerability maintains an inactive status on exploitation tracking lists, and the extremely low EPSS score of 0.00004 suggests minimal real-world attack probability at this time. Organizations should prioritize patching to BC-JAVA version 1.84 or later to remediate the cryptographic deficiency.

Impacted Technologies

VendorProductVersion(s)CPE
Legion Of The Bouncy Castle Inc.BC-JAVA
>= 1.59, < 1.80.2, >= 1.81, < 1.81.1, >= 1.82, < 1.84CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Red

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
23.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 6th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk18onFixed in: 1.80.2
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk18onFixed in: 1.81.1
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk14Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk15to18Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk18onFixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-debug-jdk14Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-debug-jdk15to18Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-debug-jdk18onFixed in: 1.84

Vendor Advisories (1)

mavenGHSA-574f-3g2m-x479critical

Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks

Apr 17, 2026

References

access.redhat.com / errata/RHSA-2026:11720
access.redhat.com / errata/RHSA-2026:11721
access.redhat.com / errata/RHSA-2026:13631
access.redhat.com / errata/RHSA-2026:14272
access.redhat.com / errata/RHSA-2026:14276
access.redhat.com / errata/RHSA-2026:17668
access.redhat.com / errata/RHSA-2026:18054
access.redhat.com / errata/RHSA-2026:18055
access.redhat.com / errata/RHSA-2026:18059
access.redhat.com / errata/RHSA-2026:21772
access.redhat.com / errata/RHSA-2026:24977
access.redhat.com / security/cve/CVE-2025-14813
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2025/cve-2025-14813.json
github.com / bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3
github.com / bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f
github.com / bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813