CVE-2025-9341 describes an Uncontrolled Resource Consumption vulnerability (CWE-400) in specific versions of Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS (2.1.0) and Bouncy Castle for Java LTS (2.73.0 through 2.73.7). This flaw, located in the AESNativeCBC program files, allows for excessive resource allocation. Rated with a CVSSv4 score of 5.9 (MEDIUM), the vulnerability has a local attack vector with low attack complexity and no required user interaction. The primary impact is high availability impact (VA:H), meaning it could lead to denial-of-service conditions. Currently, there is no evidence of active exploitation, and no public exploit code (e.g., Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are also minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Legion Of The Bouncy Castle Inc. | Bouncy Castle For Java FIPS | 2.1.0CNA affecteddefault unaffected | |
| Legion Of The Bouncy Castle Inc. | Bouncy Castle For Java LTS | >= 2.73.0, <= 2.73.7CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:C/RE:M/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.