GHSA-574f-3g2m-x479
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
Quick fix
GHSA-574f-3g2m-x479 — org.bouncycastle:bcprov-jdk18on: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.80.2</version> for org.bouncycastle:bcprov-jdk18onDetails
The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).
Are you affected?
Enter the version of the package you're using.
Affected packages
1.59No fixed version published yet for org.bouncycastle:bcprov-jdk14 (maven). Pin to a known-safe version or switch to an alternative.
1.59No fixed version published yet for org.bouncycastle:bcprov-jdk15to18 (maven). Pin to a known-safe version or switch to an alternative.
1.59Fixed in: 1.80.2# pom.xml: bump <version>1.80.2</version> for org.bouncycastle:bcprov-jdk18on1.59No fixed version published yet for org.bouncycastle:bcprov-debug-jdk14 (maven). Pin to a known-safe version or switch to an alternative.
1.59No fixed version published yet for org.bouncycastle:bcprov-debug-jdk15to18 (maven). Pin to a known-safe version or switch to an alternative.
1.59No fixed version published yet for org.bouncycastle:bcprov-debug-jdk18on (maven). Pin to a known-safe version or switch to an alternative.
1.59No fixed version published yet for org.bouncycastle:bcprov-ext-jdk14 (maven). Pin to a known-safe version or switch to an alternative.
1.59No fixed version published yet for org.bouncycastle:bcprov-ext-jdk15to18 (maven). Pin to a known-safe version or switch to an alternative.
1.59No fixed version published yet for org.bouncycastle:bcprov-ext-jdk18on (maven). Pin to a known-safe version or switch to an alternative.
1.59No fixed version published yet for org.bouncycastle:bcprov-ext-debug-jdk14 (maven). Pin to a known-safe version or switch to an alternative.
1.59No fixed version published yet for org.bouncycastle:bcprov-ext-debug-jdk15to18 (maven). Pin to a known-safe version or switch to an alternative.
1.59No fixed version published yet for org.bouncycastle:bcprov-ext-debug-jdk18on (maven). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for org.bouncycastle:bcprov-jdk14 (maven). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for org.bouncycastle:bcprov-jdk15to18 (maven). Pin to a known-safe version or switch to an alternative.
1.81.0Fixed in: 1.81.1# pom.xml: bump <version>1.81.1</version> for org.bouncycastle:bcprov-jdk18onNo fixed version published yet for org.bouncycastle:bcprov-debug-jdk14 (maven). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for org.bouncycastle:bcprov-debug-jdk15to18 (maven). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for org.bouncycastle:bcprov-debug-jdk18on (maven). Pin to a known-safe version or switch to an alternative.
1.82Fixed in: 1.84# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcprov-jdk141.82Fixed in: 1.84# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcprov-jdk15to181.82Fixed in: 1.84# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcprov-jdk18on1.82Fixed in: 1.84# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcprov-debug-jdk141.82Fixed in: 1.84# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcprov-debug-jdk15to181.82Fixed in: 1.84# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcprov-debug-jdk18on0No fixed version published yet for org.bouncycastle:bcprov-debug-jdk15on (maven). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for org.bouncycastle:bcprov-jdk15on (maven). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-14813[ADVISORY]
- https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f[WEB]
- https://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3[WEB]
- https://access.redhat.com/errata/RHSA-2026:11720[WEB]
- https://access.redhat.com/errata/RHSA-2026:60248[WEB]
- https://access.redhat.com/errata/RHSA-2026:60249[WEB]
- https://access.redhat.com/errata/RHSA-2026:60250[WEB]
- https://access.redhat.com/errata/RHSA-2026:60251[WEB]
- https://access.redhat.com/errata/RHSA-2026:60252[WEB]
- https://access.redhat.com/errata/RHSA-2026:60254[WEB]
- https://access.redhat.com/errata/RHSA-2026:60256[WEB]
- https://access.redhat.com/errata/RHSA-2026:60259[WEB]
- https://access.redhat.com/errata/RHSA-2026:66488[WEB]
- https://access.redhat.com/security/cve/CVE-2025-14813[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2458640[WEB]
- https://github.com/bcgit/bc-java[PACKAGE]
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813[WEB]
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json[WEB]
- https://access.redhat.com/errata/RHSA-2026:11721[WEB]
- https://access.redhat.com/errata/RHSA-2026:13631[WEB]
- https://access.redhat.com/errata/RHSA-2026:14272[WEB]
- https://access.redhat.com/errata/RHSA-2026:14276[WEB]
- https://access.redhat.com/errata/RHSA-2026:17668[WEB]
- https://access.redhat.com/errata/RHSA-2026:18054[WEB]
- https://access.redhat.com/errata/RHSA-2026:18055[WEB]
- https://access.redhat.com/errata/RHSA-2026:18059[WEB]
- https://access.redhat.com/errata/RHSA-2026:21772[WEB]
- https://access.redhat.com/errata/RHSA-2026:24977[WEB]
- https://access.redhat.com/errata/RHSA-2026:53644[WEB]
- https://access.redhat.com/errata/RHSA-2026:53645[WEB]
- https://access.redhat.com/errata/RHSA-2026:53646[WEB]
- https://access.redhat.com/errata/RHSA-2026:53806[WEB]
- https://access.redhat.com/errata/RHSA-2026:60239[WEB]
- https://access.redhat.com/errata/RHSA-2026:60246[WEB]
- https://access.redhat.com/errata/RHSA-2026:60247[WEB]