Broken GOSTCTR Algorithm in Bouncy Castle BC-Java bcprov <1.84
CVE-2025-14813 Published on April 15, 2026
GOSTCTR implementation unable to process more than 255 blocks correctly
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).
This vulnerability is associated with program files G3413CTRBlockCipher.
This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Vulnerability Analysis
CVE-2025-14813 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Use of a Broken or Risky Cryptographic Algorithm
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information. The use of a non-standard algorithm is dangerous because a determined attacker may be able to break the algorithm and compromise whatever data has been protected. Well-known techniques may exist to break the algorithm.
Products Associated with CVE-2025-14813
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-14813 are published in these products:
Affected Versions
Legion of the Bouncy Castle Inc. BC-JAVA:- Version 1.59 and below 1.80.2 is affected.
- Version 1.81 and below 1.81.1 is affected.
- Version 1.82 and below 1.84 is affected.
- Version debug-jdk15on and below * is unaffected.
- Version 0:2.16.0-22.redhat_00057.1.el7eap and below * is unaffected.
- Version 0:2.3.14-11.SP11_redhat_00001.1.el7eap and below * is unaffected.
- Version 0:1.5.26-2.Final_redhat_00001.1.el7eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el7eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el7eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el7eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el7eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el7eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el7eap and below * is unaffected.
- Version 0:5.0.31-3.SP2_redhat_00001.1.el7eap and below * is unaffected.
- Version 0:1.10.0-46.Final_redhat_00044.1.el7eap and below * is unaffected.
- Version 0:4.1.135-1.Final_redhat_00001.1.el7eap and below * is unaffected.
- Version 0:4.1.135-1.Final_redhat_00001.1.el7eap and below * is unaffected.
- Version 0:2.5.5-30.SP12_redhat_00020.1.el7eap and below * is unaffected.
- Version 0:2.5.5-24.SP12_redhat_00016.1.el7eap and below * is unaffected.
- Version 0:2.2.40-2.SP3_redhat_00001.1.el7eap and below * is unaffected.
- Version 0:7.4.25-2.GA_redhat_00001.1.el7eap and below * is unaffected.
- Version 0:2.16.0-22.redhat_00057.1.el8eap and below * is unaffected.
- Version 0:2.3.14-11.SP11_redhat_00001.1.el8eap and below * is unaffected.
- Version 0:1.5.26-2.Final_redhat_00001.1.el8eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el8eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el8eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el8eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el8eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el8eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el8eap and below * is unaffected.
- Version 0:5.0.31-3.SP2_redhat_00001.1.el8eap and below * is unaffected.
- Version 0:1.10.0-46.Final_redhat_00044.1.el8eap and below * is unaffected.
- Version 0:4.1.135-1.Final_redhat_00001.1.el8eap and below * is unaffected.
- Version 0:4.1.135-1.Final_redhat_00001.1.el8eap and below * is unaffected.
- Version 0:2.5.5-30.SP12_redhat_00020.1.el8eap and below * is unaffected.
- Version 0:2.5.5-24.SP12_redhat_00016.1.el8eap and below * is unaffected.
- Version 0:2.2.40-1.SP3_redhat_00001.1.el8eap and below * is unaffected.
- Version 0:7.4.25-2.GA_redhat_00001.1.el8eap and below * is unaffected.
- Version 0:2.16.0-22.redhat_00057.1.el9eap and below * is unaffected.
- Version 0:2.3.14-11.SP11_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:1.5.26-2.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el9eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el9eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el9eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el9eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el9eap and below * is unaffected.
- Version 0:2.18.8-1.redhat_00003.1.el9eap and below * is unaffected.
- Version 0:5.0.31-3.SP2_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:1.10.0-46.Final_redhat_00044.1.el9eap and below * is unaffected.
- Version 0:4.1.135-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:4.1.135-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:2.5.5-30.SP12_redhat_00020.1.el9eap and below * is unaffected.
- Version 0:2.5.5-24.SP12_redhat_00016.1.el9eap and below * is unaffected.
- Version 0:2.2.40-1.SP3_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:7.4.25-2.GA_redhat_00001.1.el9eap and below * is unaffected.
- Version 1.84.0.redhat-00001 and below * is unaffected.
- Version 0:1.84.0-1.redhat_00001.1.el8eap and below * is unaffected.
- Version 0:1.84.0-1.redhat_00001.1.el9eap and below * is unaffected.
- Version 1786628667 and below * is unaffected.
- Version 1786628681 and below * is unaffected.
- Version 1786533561 and below * is unaffected.
- Version 1786533565 and below * is unaffected.
- Version 1787125166 and below * is unaffected.
- Version 1787124635 and below * is unaffected.
- Version 1787125069 and below * is unaffected.
- Version 1787124632 and below * is unaffected.
- Version 1787124925 and below * is unaffected.
- Version 1787125311 and below * is unaffected.
- Version 1787124779 and below * is unaffected.
- Version 1780069506 and below * is unaffected.
- Version 1779528224 and below * is unaffected.
- Version 1779359423 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.