Broken GOSTCTR Algorithm in Bouncy Castle BC-Java bcprov <1.84
CVE-2025-14813 Published on April 15, 2026
GOSTCTR implementation unable to process more than 255 blocks correctly
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).
This vulnerability is associated with program files G3413CTRBlockCipher.
This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Vulnerability Analysis
CVE-2025-14813 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Privileges Required:
NONE
Confidentiality Impact:
HIGH
Availability Impact:
NONE
Weakness Type
Use of a Broken or Risky Cryptographic Algorithm
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information. The use of a non-standard algorithm is dangerous because a determined attacker may be able to break the algorithm and compromise whatever data has been protected. Well-known techniques may exist to break the algorithm.
Products Associated with CVE-2025-14813
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-14813 are published in these products:
Affected Versions
Legion of the Bouncy Castle Inc.
BC-JAVA:
-
Version 1.59 and below 1.80.2
is affected.
-
Version 1.81 and below 1.81.1
is affected.
-
Version 1.82 and below 1.84
is affected.
Red Hat AMQ Broker 7.12.7:
Red Hat AMQ Broker 7.13.5:
Red Hat Build of Apache Camel 4.14 for Quarkus 3.27:
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14:
-
Version debug-jdk15on and below *
is unaffected.
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14:
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14:
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14:
Red Hat build of Quarkus 3.20.6.SP1:
Red Hat build of Quarkus 3.27.3.SP1:
Red Hat JBoss Enterprise Application Platform 8.1:
-
Version ext-jdk15on and below *
is unaffected.
-
Version ext-jdk18on and below *
is unaffected.
Red Hat JBoss Enterprise Application Platform 8.1:
Red Hat JBoss Enterprise Application Platform 8.1:
Red Hat JBoss Enterprise Application Platform 8.1:
Red Hat JBoss Enterprise Application Platform 8.1:
Red Hat JBoss Enterprise Application Platform 8.1:
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8:
-
Version 0:1.84.0-1.redhat_00001.1.el8eap and below *
is unaffected.
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9:
-
Version 0:1.84.0-1.redhat_00001.1.el9eap and below *
is unaffected.
Red Hat OpenShift AI 2.25:
-
Version 1780069506 and below *
is unaffected.
Red Hat OpenShift Dev Spaces 3.28:
-
Version 1779528224 and below *
is unaffected.
Red Hat OpenShift Dev Spaces 3.28:
-
Version 1779359423 and below *
is unaffected.
Red Hat
Cryostat 4:
Red Hat
OpenShift Developer Tools and Services:
Red Hat
OpenShift Developer Tools and Services:
Red Hat
OpenShift Developer Tools and Services:
Red Hat
OpenShift Developer Tools and Services:
Red Hat AMQ Broker 7:
Red Hat AMQ Clients:
Red Hat AMQ Clients:
Red Hat build of Apache Camel 4 for Quarkus 3:
Red Hat build of Apicurio Registry 3:
Red Hat build of Apicurio Registry 3:
Red Hat build of Debezium 3:
Red Hat build of Debezium 3:
Red Hat build of Debezium 3:
Red Hat Build of Keycloak:
Red Hat Data Grid 8:
Red Hat Data Grid 8:
Red Hat Data Grid 8:
Red Hat Data Grid 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Fuse 7:
Red Hat Fuse 7:
Red Hat Fuse 7:
Red Hat Fuse 7:
Red Hat Fuse 7:
Red Hat Fuse 7:
Red Hat Fuse 7:
Red Hat Fuse 7:
Red Hat JBoss Enterprise Application Platform 7:
Red Hat JBoss Enterprise Application Platform 7:
Red Hat JBoss Enterprise Application Platform 7:
Red Hat JBoss Enterprise Application Platform 7:
Red Hat JBoss Enterprise Application Platform Expansion Pack:
Red Hat JBoss Enterprise Application Platform Expansion Pack:
Red Hat JBoss Enterprise Application Platform Expansion Pack:
Red Hat JBoss Enterprise Application Platform Expansion Pack:
Red Hat JBoss Enterprise Application Platform Expansion Pack:
Red Hat JBoss Enterprise Application Platform Expansion Pack:
Red Hat JBoss Enterprise Application Platform Expansion Pack:
Red Hat JBoss Enterprise Application Platform Expansion Pack:
Red Hat OpenShift AI (RHOAI):
Red Hat Process Automation 7:
Red Hat Process Automation 7:
Red Hat Satellite 6:
Red Hat Satellite 6:
Red Hat Single Sign-On 7:
Red Hat
streams for Apache Kafka 2:
Red Hat
streams for Apache Kafka 2:
Red Hat
streams for Apache Kafka 3:
Red Hat
streams for Apache Kafka 3:
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.