CVE-2025-8885 - CVE House
Back to Database
Status published Medium CVE-2025-8885

Possible DOS in processing specially formed ASN.1 Object Identifiers

Vulnerability Description

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdenti... https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java . This issue affects BC Java: from 1.0 through 1.77; BC-FJA: from 1.0.0 through 1.0.2.5, from 2.0.0 through 2.0.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8885

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Bing Shi

Affected Vendor

Legion of the Bouncy Castle Inc.

View all reports →

Affected Software

BC Java, BC-FJA
Vulnerable Versions:
1.0, 1.0.0, 2.0.0

Timeline

Official Publish: August 12th, 2025
Last Modified: September 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)