VYPR
High severity7.5GHSA Advisory· Published May 14, 2024· Updated Apr 15, 2026

CVE-2024-29857

CVE-2024-29857

Description

An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.bouncycastle:bcprov-jdk18onMaven
< 1.781.78
org.bouncycastle:bcprov-jdk15onMaven
< 1.781.78
org.bouncycastle:bcprov-jdk15to18Maven
< 1.781.78
org.bouncycastle:bcprov-jdk14Maven
< 1.781.78
org.bouncycastle:bctls-jdk18onMaven
< 1.781.78
org.bouncycastle:bctls-jdk14Maven
< 1.781.78
org.bouncycastle:bctls-jdk15to18Maven
< 1.781.78
org.bouncycastle:bc-fipsMaven
< 1.0.2.51.0.2.5
BouncyCastleNuGet
>= 0
BouncyCastle.CryptographyNuGet
< 2.3.12.3.1

Affected products

198

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.