{"id":"CVE-2025-9092","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-9092","summary":"Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability","details":"Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader.\n\nThis issue affects Bouncy Castle for Java - BC-FJA 2.1.0: from BC-FJA 2.1.0 through 2.1.0.","published":"2025-08-16T12:30:32Z","modified":"2026-09-10T03:50:27.571552436Z","cvss":null,"epss":{"score":0.00147,"percentile":0.0429,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.bouncycastle:bc-fips","fixedVersion":"2.1.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9092"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"},{"type":"WEB","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%909092"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:27.571552436Z"}}