OER parser recurses without depth limit on self-referential IEEE 1609.2 schema
Published Aug 3, 2026
8.7
HIGHCVSS 4.0
EPSS 0.49%
Description
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Affected products
-
- Version 2.0.0StatusaffectedConstraints<2.0.7
- Version 2.1.0StatusaffectedConstraints<2.1.7
- Version
-
- Version 1.70StatusaffectedConstraints<1.85
- Version
-
- Version 2.73.0StatusaffectedConstraints<2.73.12
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-Fja | unaffected |
| |||||||||
| Legion of the Bouncy Castle Inc. | BC-Java | unaffected |
| |||||||||
| Legion of the Bouncy Castle Inc. | BC-Lts-Java | unaffected |
|
- < 1.85
- ≥ 2.0.2 · < 2.0.7
- ≥ 2.1.4 · < 2.1.7
- ≤ 2.73.11
No data.
Red Hat AMQ Clients
bcprov-jdk15on
Not affected
Red Hat Enterprise Linux 8
pki-core:10.6/resteasy
Not affected
Red Hat Enterprise Linux 8
pki-deps:10.6/resteasy
Affected
Red Hat Enterprise Linux 9
resteasy
Affected
Red Hat JBoss Enterprise Application Platform 7
bcprov-jdk15on
Will not fix
Red Hat Single Sign-On 7
bcprov-jdk15on
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Clients | bcprov-jdk15on | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Affected | n/a |
| Red Hat Enterprise Linux 9 | resteasy | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | bcprov-jdk15on | Will not fix | n/a |
| Red Hat Single Sign-On 7 | bcprov-jdk15on | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Bouncy Castle for Java is bundled as a cryptographic provider across numerous Red Hat products. The OER (Octet Encoding Rules) parser recurses without a depth limit on a self-referential IEEE 1609.2 schema, so a crafted schema causes resource exhaustion and a denial of service. This is reachable only via the OER / IEEE 1609.2 (V2X) code paths, a narrow surface for most products.
Red Hat mitigation
Red Hat is not aware of a mitigation for this flaw other than updating the affected Bouncy Castle component to a fixed version (bc-java 1.85, LTS 2.73.12, or BC-FJA bcutil-fips 2.0.7/2.1.7) once available for the affected product.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-59645 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2510189 Issue Tracking
- https://github.com/bcgit/bc-java/commit/822b2478b131097368a56290f5728e28dd042989 patch
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059645 vendor-advisoryThird Party Advisory
- https://github.com/bcgit/bc-java/wiki/CVE-2026-59645
- https://nvd.nist.gov/vuln/detail/CVE-2026-59645
- https://www.cve.org/CVERecord?id=CVE-2026-59645
Change history (0)
No recorded changes yet.