In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
{
"cna_assigner": "bcorg",
"cwe_ids": [
"CWE-770"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58063.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.0.2.7"
},
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.2"
},
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.3"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-58063.json"
"2026-08-12T13:45:43Z"
[
{
"source": "https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06",
"target": {
"file": "core/src/main/java/org/bouncycastle/util/Properties.java"
},
"digest": {
"line_hashes": [
"102651598719612461451204318068968325585",
"45230238234468642547860643575581980889",
"45297522555882596788886510719769951710"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2026-58063-24a62c2a",
"signature_version": "v1",
"signature_type": "Line"
},
{
"source": "https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06",
"target": {
"file": "prov/src/test/java/org/bouncycastle/jce/provider/test/BCFKSStoreTest.java",
"function": "performTest"
},
"digest": {
"length": 399.0,
"function_hash": "97196642524409049649824429503537352657"
},
"deprecated": false,
"id": "CVE-2026-58063-5c1fdcd3",
"signature_version": "v1",
"signature_type": "Function"
},
{
"source": "https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bcfks/BcFKSKeyStoreSpi.java"
},
"digest": {
"line_hashes": [
"52735969277755972319211395169986010495",
"37930698598735065658556292559111878312",
"141114084220270166850116115141431571984",
"166035425026678193671729998394606564311",
"225626380489405269104715269151364318916",
"292634780617619332889139604890451192372",
"325956569862363410016853153935791915865",
"276115914328855788695834149212072069889",
"100429293740405568076594451812474225985",
"241760984190654916609945876961612791919",
"12298676889607508769847130270862071315",
"79810701464363562744460575882078485044",
"299340804217310855482500297926272283722",
"228555034051567588578380853872627580395",
"242441938689742431963436339022593438351",
"158298485265166454375483893411483821864",
"213923787035075464562176740043893479855",
"202700449113950706550844458781072309853",
"21870324310364645205116478137299433652",
"238445397402305358910154435405945210162",
"247391813297522763209654971806349487658"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2026-58063-70b24ee7",
"signature_version": "v1",
"signature_type": "Line"
},
{
"source": "https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bcfks/BcFKSKeyStoreSpi.java",
"function": "generateKey"
},
"digest": {
"length": 1904.0,
"function_hash": "218960289093608826246302666792098092840"
},
"deprecated": false,
"id": "CVE-2026-58063-8097358b",
"signature_version": "v1",
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"338161456638555766921199886431436869791",
"173828105648014912990161709748026415950",
"97272610387377278181521148572206283987",
"242584727117918079787187061696704271203",
"42547155967706318575404851863590496751",
"157038091547283557145346192168268264519",
"247692343243261867057722127100943046923",
"134755098599701129349015599864694467487",
"30662707321350791038220568122002092172",
"31778482086692356249693773966818830123",
"149841401896403592467565652782917859241"
],
"threshold": 0.9
},
"source": "https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06",
"target": {
"file": "prov/src/test/java/org/bouncycastle/jce/provider/test/BCFKSStoreTest.java"
},
"id": "CVE-2026-58063-d60b0397",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line"
}
]