{"id":"CVE-2025-9340","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-9340","summary":"Bouncy Castle for Java has Out-of-Bounds Write Vulnerability","details":"Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher.\n\nThis issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.","published":"2025-08-22T12:30:30Z","modified":"2025-08-22T21:27:30.751452Z","cvss":null,"epss":{"score":0.00169,"percentile":0.06622,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.bouncycastle:bc-fips","fixedVersion":"2.1.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9340"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"},{"type":"WEB","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%909340"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-08-22T21:27:30.751452Z"}}