Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
☕ Maven
Not in CISA KEV

CVE-2025-14813 — bcprov-jdk14

Fix: bcgit/bc-java@701686c

CVE-2025-14813 is a Broken Cryptographic Algorithm vulnerability in org.bouncycastle:bcprov-jdk14. A fix is available for org.bouncycastle:bcprov-jdk14 — see the affected versions and patch details below.

GOSTCTR implementation unable to process more than 255 blocks correctly

Also known asGHSA-574f-3g2m-x479
Published
Apr 15, 2026
Updated
Sep 20, 2026
Affected
26 pkgs
Patched
8 / 26
Exploits
None indexed
Exploitation data as of Sep 28, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2025-14813.

EPSS Exploitation Probability

via FIRST.org ↗
0.3%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs22th percentile — riskier than 22% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

26 pkgs affected
☕org.bouncycastle:bcprov-jdk14☕org.bouncycastle:bcprov-jdk15to18☕org.bouncycastle:bcprov-jdk18on☕org.bouncycastle:bcprov-debug-jdk14☕org.bouncycastle:bcprov-debug-jdk15to18☕org.bouncycastle:bcprov-debug-jdk18on☕org.bouncycastle:bcprov-ext-jdk14☕org.bouncycastle:bcprov-ext-jdk15to18+18 more

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.

Description

The GOST 28147-2015 CTR mode implementation (G3413CTRBlockCipher) in the Legion of the Bouncy Castle BC-JAVA bcprov core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).

Affected Packages

26 total 8 fixed
EcosystemPackageVulnerable rangeFix
☕Mavenorg.bouncycastle:bcprov-jdk14≥ 1.59No fix
☕Mavenorg.bouncycastle:bcprov-jdk15to18≥ 1.59No fix
☕Mavenorg.bouncycastle:bcprov-jdk18on≥ 1.59&&< 1.80.21.80.2org.bouncycastle:bcprov-jdk18on:1.80.2
☕Mavenorg.bouncycastle:bcprov-debug-jdk14≥ 1.59No fix
☕Mavenorg.bouncycastle:bcprov-debug-jdk15to18≥ 1.59No fix
☕Mavenorg.bouncycastle:bcprov-debug-jdk18on≥ 1.59No fix

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for org.bouncycastle:bcprov-jdk14, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    No patched version of org.bouncycastle:bcprov-jdk14 has shipped for CVE-2025-14813 yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatImportant

To exploit this flaw, an attacker needs to capture ciphertext encrypted by the `GOSTCTR` implementation where the `G3413CTRBlockCipher` processed more than 255 blocks of data, resulting in keystream reuse. An attack typically requires capturing these overlapping ciphertexts to perform cryptanalysis and uncover the…

Workaround published by Red Hat
To mitigate this vulnerability, strictly limit the payload encrypted under a single key and Initialization Vector (IV) pair using the GOSTCTR implementation and G3413CTRBlockCipher to a maximum of 255 blocks. Alternatively, transition to a more secure, standardized and authenticated encryption mode.
Source: Red Hat security advisory for CVE-2025-14813 (CC BY 4.0)
ProductFixed inAdvisory
Red Hat AMQ Broker 7.12.7bcprov-jdk18onRHSA-2026:14276
Red Hat AMQ Broker 7.13.5bcprov-jdk18onRHSA-2026:14272
Red Hat AMQ Broker 7.14.1bcprov-jdk18onRHSA-2026:66488
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14bcprov-debug-jdk15onRHSA-2026:17668
Red Hat build of Quarkus 3.20.6.SP1bcprov-jdk18onRHSA-2026:11720
Red Hat build of Quarkus 3.27.3.SP1bcprov-jdk18onRHSA-2026:11721
Red Hat JBoss Enterprise Application Platform 7.4.25org.bouncycastle/bcprov-jdk18on:1.84.0.redhat-00001RHSA-2026:53806
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-activemq-artemis-0:2.16.0-22.redhat_00057.1.el7eapRHSA-2026:53644

Frequently Asked Questions

The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).
O3 Security · Impact-Aware SCA

Is CVE-2025-14813 in your dependencies?

Find it across Maven, including transitive dependencies.

CVE-2025-14813: bcprov-jdk14 | O3 Security