Back

HIGH

OER parser recurses without depth limit on self-referential IEEE 1609.2 schema

Published Aug 3, 2026

Description

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).

Affected products

Remediation

Red Hat statement

Bouncy Castle for Java is bundled as a cryptographic provider across numerous Red Hat products. The OER (Octet Encoding Rules) parser recurses without a depth limit on a self-referential IEEE 1609.2 schema, so a crafted schema causes resource exhaustion and a denial of service. This is reachable only via the OER / IEEE 1609.2 (V2X) code paths, a narrow surface for most products.

Red Hat mitigation

Red Hat is not aware of a mitigation for this flaw other than updating the affected Bouncy Castle component to a fixed version (bc-java 1.85, LTS 2.73.12, or BC-FJA bcutil-fips 2.0.7/2.1.7) once available for the affected product.

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner bcorg
Published Aug 3, 2026
Updated Aug 3, 2026
Reserved Jul 6, 2026
CISA Vulnrichment
Updated Aug 3, 2026
NVD
Status Analyzed
Modified Aug 28, 2026
Red Hat
Severity Important
Public date Aug 3, 2026