In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
{
"cwe_ids": [
"CWE-674"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13506.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.0.2.7"
},
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.2"
},
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.3"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "bcorg"
}[
{
"target": {
"file": "core/src/main/java/org/bouncycastle/asn1/LazyEncodedSequence.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"158376567645657653324906633439317214072",
"178987754787345110035959588099764548021",
"143798232643951361169023482570136452533",
"26033248155714495977648867109508160371",
"327531848570331354873769916640808998975",
"286513508805288261787221284009401024444",
"169118947633146647780919924025519079288",
"179967981643364087700804152959277943599",
"235518759519465125929271491855024393324",
"190549334398300417841863707758724948408",
"250771986070911238968187114863236633590",
"95133746975837850381520346158669449626",
"44730602083560976904692731090949657874",
"21912970204439823143656867629174961234",
"198223294896821837129891129093273158308",
"213677019924696639351291435738125937788",
"277045168928185191249373788468073340545"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2026-13506-0627e29f",
"source": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84",
"signature_type": "Line"
},
{
"target": {
"file": "core/src/main/java/org/bouncycastle/asn1/LazyConstructionEnumeration.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"235457360955085730454699112928777982478",
"336009989662821671552924520477957398067",
"77269822213180218469371405697138551265",
"138515488786954600116548911032652396525",
"51423723131371566398795530408893150056",
"336466190124490083861064336257689580648"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2026-13506-22cdba6a",
"source": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84",
"signature_type": "Line"
},
{
"signature_version": "v1",
"target": {
"file": "core/src/test/java/org/bouncycastle/asn1/test/ASN1SequenceParserTest.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"314758280572643044558563110554852413886",
"279797251563039921670446787047900557131",
"281407350321223523799786807762596159592",
"30043312945700738458806914298563788495",
"97165517800669256375895453245299882071",
"78439715858504619994758078134621618769",
"319148722460724520532805245972191596496",
"305527499925751219789390222671358337237",
"329919450933684611360907959398918239035",
"228060717886308006480593776668976070242",
"172720208936570201446559394414316098547",
"129776403487741460731825231674457638494",
"47639522888115786713446624097484335120",
"319501541711497073604550233393921136970",
"241833789705695161255311056777726096731"
],
"threshold": 0.9
},
"source": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84",
"id": "CVE-2026-13506-30f877d6",
"signature_type": "Line"
},
{
"target": {
"file": "core/src/main/java/org/bouncycastle/asn1/LazyEncodedSequence.java",
"function": "force"
},
"deprecated": false,
"digest": {
"function_hash": "144639706464096128163206613379610177590",
"length": 298.0
},
"signature_version": "v1",
"id": "CVE-2026-13506-45c6b2a0",
"source": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84",
"signature_type": "Function"
},
{
"deprecated": false,
"digest": {
"function_hash": "164235855366415641138107437510214998227",
"length": 91.0
},
"signature_version": "v1",
"target": {
"file": "core/src/main/java/org/bouncycastle/asn1/LazyConstructionEnumeration.java",
"function": "LazyConstructionEnumeration"
},
"id": "CVE-2026-13506-77b5fd03",
"source": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84",
"signature_type": "Function"
},
{
"source": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84",
"target": {
"file": "core/src/main/java/org/bouncycastle/asn1/ASN1InputStream.java",
"function": "buildObject"
},
"deprecated": false,
"digest": {
"function_hash": "53992758034096463192460910559195542256",
"length": 970.0
},
"id": "CVE-2026-13506-a14c7db2",
"signature_version": "v1",
"signature_type": "Function"
},
{
"signature_version": "v1",
"target": {
"file": "core/src/main/java/org/bouncycastle/asn1/LazyEncodedSequence.java",
"function": "getObjects"
},
"deprecated": false,
"digest": {
"function_hash": "200247900279389207162872454646252423791",
"length": 132.0
},
"source": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84",
"id": "CVE-2026-13506-abb1df1f",
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"32866915942599558974924613436752160149",
"170743825630536781131524958930231413332",
"148474808762847297273485234935540302023",
"314494502992072357285132705685938831936",
"66706847725628709014224436443315078904",
"316603059222462909723381583854336853464",
"267921782967147066617121850831103281045"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "core/src/main/java/org/bouncycastle/asn1/ASN1InputStream.java"
},
"deprecated": false,
"id": "CVE-2026-13506-e28df0eb",
"source": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84",
"signature_type": "Line"
},
{
"target": {
"file": "core/src/main/java/org/bouncycastle/asn1/LazyEncodedSequence.java",
"function": "LazyEncodedSequence"
},
"deprecated": false,
"digest": {
"function_hash": "249944058971922663830407914701470125906",
"length": 159.0
},
"signature_version": "v1",
"id": "CVE-2026-13506-e8fcc6ed",
"source": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-13506.json"
"2026-08-12T15:33:34Z"