Broken GOSTCTR Algorithm in Bouncy Castle BC-Java bcprov <1.84
CVE-2025-14813 Published on April 15, 2026

GOSTCTR implementation unable to process more than 255 blocks correctly
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2025-14813 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Type

Use of a Broken or Risky Cryptographic Algorithm

The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information. The use of a non-standard algorithm is dangerous because a determined attacker may be able to break the algorithm and compromise whatever data has been protected. Well-known techniques may exist to break the algorithm.


Products Associated with CVE-2025-14813

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-14813 are published in these products:

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

Legion of the Bouncy Castle Inc. BC-JAVA: Red Hat JBoss EAP 8.1 for RHEL 8: Red Hat JBoss EAP 8.1 for RHEL 9: Red Hat AMQ Broker 7.12.7: Red Hat AMQ Broker 7.13.5: Red Hat Build of Apache Camel 4.14 for Quarkus 3.27: Red Hat JBoss Enterprise Application Platform 8.1: Red Hat OpenShift AI 2.25: Red Hat OpenShift Dev Spaces 3.28: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14: Red Hat build of Quarkus 3.20.6.SP1: Red Hat build of Quarkus 3.27.3.SP1: Red Hat OpenShift Developer Tools and Services: Red Hat AMQ Clients: Red Hat build of Apache Camel 4 for Quarkus 3: Red Hat build of Apicurio Registry 3: Red Hat build of Debezium 3: Red Hat Build of Keycloak: Red Hat Enterprise Linux 8: Red Hat Enterprise Linux 9: Red Hat Fuse 7: Red Hat JBoss Enterprise Application Platform 7: Red Hat OpenShift AI (RHOAI): Red Hat Process Automation 7: Red Hat Single Sign-On 7: Red Hat streams for Apache Kafka 2: Red Hat Cryostat 4: Red Hat AMQ Broker 7: Red Hat Data Grid 8: Red Hat JBoss Enterprise Application Platform Expansion Pack: Red Hat Satellite 6: Red Hat streams for Apache Kafka 3:

Exploit Probability

EPSS
0.12%
Percentile
1.85%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.