{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/bouncy-castle/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bouncy Castle for Java FIPS"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","java","library-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Bouncy Castle"],"content_html":"\u003cp\u003eThe Bouncy Castle for Java FIPS (Federal Information Processing Standards) library has been identified as containing multiple vulnerabilities that may be exploited by remote, anonymous attackers to cause a denial-of-service (DoS) condition. Bouncy Castle is a widely used set of cryptographic APIs for the Java platform. Successful exploitation of these flaws disrupts the availability of services that rely on this library for cryptographic operations. Because this is a library-level vulnerability, the impact is highly dependent on how the underlying application implements the affected cryptographic components. Defenders should audit applications to identify dependencies on the FIPS-certified Bouncy Castle version and monitor for vendor updates to mitigate the availability risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial-of-service condition for applications leveraging the affected Bouncy Castle for Java FIPS library. This can lead to service outages and the inability of systems to perform essential cryptographic functions, impacting business continuity. The specific number of victims is currently unknown, but the library is pervasive in enterprise Java environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an inventory of all Java applications to identify those incorporating the Bouncy Castle for Java FIPS library.\u003c/li\u003e\n\u003cli\u003ePrioritize patching as soon as the vendor releases security updates for the affected FIPS-certified versions.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for abnormal resource consumption or unexpected crash loops (Java stack traces) in cryptographic service modules.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T13:26:31Z","date_published":"2026-08-10T13:26:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-bouncy-castle-dos/","summary":"Multiple vulnerabilities in the Bouncy Castle for Java FIPS library allow remote, anonymous attackers to trigger a denial-of-service condition.","title":"Denial of Service Vulnerabilities in Bouncy Castle for Java FIPS","url":"https://feed.craftedsignal.io/briefs/2026-08-bouncy-castle-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Bouncy Castle","version":"https://jsonfeed.org/version/1.1"}