CVE-2025-14813 — bcprov-jdk14
Fix: bcgit/bc-java@701686cCVE-2025-14813 is a Broken Cryptographic Algorithm vulnerability in org.bouncycastle:bcprov-jdk14. A fix is available for org.bouncycastle:bcprov-jdk14 — see the affected versions and patch details below.
GOSTCTR implementation unable to process more than 255 blocks correctly
Exploitation Status
No confirmed exploitation observed yet
- A successful exploit gives an attacker total control of the affected component, not partial access.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2025-14813.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
org.bouncycastle:bcprov-jdk14☕org.bouncycastle:bcprov-jdk15to18☕org.bouncycastle:bcprov-jdk18on☕org.bouncycastle:bcprov-debug-jdk14☕org.bouncycastle:bcprov-debug-jdk15to18☕org.bouncycastle:bcprov-debug-jdk18on☕org.bouncycastle:bcprov-ext-jdk14☕org.bouncycastle:bcprov-ext-jdk15to18+18 moreReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.
Description
The GOST 28147-2015 CTR mode implementation (G3413CTRBlockCipher) in the Legion of the Bouncy Castle BC-JAVA bcprov core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| ☕Maven | org.bouncycastle:bcprov-jdk14 | ≥ 1.59 | No fix |
| ☕Maven | org.bouncycastle:bcprov-jdk15to18 | ≥ 1.59 | No fix |
| ☕Maven | org.bouncycastle:bcprov-jdk18on | ≥ 1.59&&< 1.80.2 | 1.80.2org.bouncycastle:bcprov-jdk18on:1.80.2 |
| ☕Maven | org.bouncycastle:bcprov-debug-jdk14 | ≥ 1.59 | No fix |
| ☕Maven | org.bouncycastle:bcprov-debug-jdk15to18 | ≥ 1.59 | No fix |
| ☕Maven | org.bouncycastle:bcprov-debug-jdk18on | ≥ 1.59 | No fix |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for org.bouncycastle:bcprov-jdk14, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
No patched version of org.bouncycastle:bcprov-jdk14 has shipped for CVE-2025-14813 yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
To exploit this flaw, an attacker needs to capture ciphertext encrypted by the `GOSTCTR` implementation where the `G3413CTRBlockCipher` processed more than 255 blocks of data, resulting in keystream reuse. An attack typically requires capturing these overlapping ciphertexts to perform cryptanalysis and uncover the…
To mitigate this vulnerability, strictly limit the payload encrypted under a single key and Initialization Vector (IV) pair using the GOSTCTR implementation and G3413CTRBlockCipher to a maximum of 255 blocks. Alternatively, transition to a more secure, standardized and authenticated encryption mode.Source: Red Hat security advisory for CVE-2025-14813 (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat AMQ Broker 7.12.7 | bcprov-jdk18on | RHSA-2026:14276 |
| Red Hat AMQ Broker 7.13.5 | bcprov-jdk18on | RHSA-2026:14272 |
| Red Hat AMQ Broker 7.14.1 | bcprov-jdk18on | RHSA-2026:66488 |
| Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 | bcprov-debug-jdk15on | RHSA-2026:17668 |
| Red Hat build of Quarkus 3.20.6.SP1 | bcprov-jdk18on | RHSA-2026:11720 |
| Red Hat build of Quarkus 3.27.3.SP1 | bcprov-jdk18on | RHSA-2026:11721 |
| Red Hat JBoss Enterprise Application Platform 7.4.25 | org.bouncycastle/bcprov-jdk18on:1.84.0.redhat-00001 | RHSA-2026:53806 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-activemq-artemis-0:2.16.0-22.redhat_00057.1.el7eap | RHSA-2026:53644 |
Frequently Asked Questions
Is CVE-2025-14813 in your dependencies?
Find it across Maven, including transitive dependencies.