CVE-2026-17508

MEDIUMPre-NVD 5.35.3—
EchelonGraph scoreMEDIUM confidence

This medium-severity CVE scores 5.3 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.4% (35th percentile of EPSS-scored CVEs). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).

Triggered by: NVD CVSS baseline
Sources: epss, secondary
Trending — 4 sources updated this week
5.3EG
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS PROB: 0.4%CVSS: 5.3Exploit: None knownExposed services: Not assessed

An upstream fix is merged but not yet released — mitigate (WAF / firewall / segmentation) until the release ships, then apply it.

In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an arbitrary amount of work before any password or integrity check could reject it. The affected paths are the RFC 9579 PBMAC1 MAC calculator builders, which took the PBKDF2 iteration count and derived-key length straight out of PBMAC1Params (JcePBMac1CalculatorBuilder, and PKCS12PBEUtils.createPBMac1Calculator reached from PKCS12PfxPdu.isMacValid); the scrypt parallelization parameter p in the PKCS#8 and PKCS#12 cost guards, which bounded only the cost parameter N and the block size r even though the scratch buffer scales with r times p, so the configured memory ceiling could be evaded entirely; the raw JCA PBKDF2 provider (org.bouncycastle.jcajce.provider.symmetric.PBEPBKDF2); and the bcrypt round count read from an encrypted OpenSSH v1 private key's own kdfoptions. Each now bounds the parameter before deriving, in line with the caps already applied elsewhere in the tree, with the OpenSSH round count configurable through the new org.bouncycastle.openssh.max_rounds property. This completes the bounding begun in 1.85 for the PKCS#8 / PBES2 decryptors (CVE-2026-15055). This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

CVSS v3
5.3
EG Score
5.3MEDIUMmedium confidence
EG Risk
24
EG Risk 24/100CISA SSVC

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity53% × 45%
Exploitation0% × 40%
Automatability0% × 15%
CISA SSVC: Track at every mission impact level.
Action: An upstream fix is merged but not yet in a tagged release. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines until it ships, then apply the release.
EPSS PROB
0.4%
EPSS %ILE
35th
KEV
Not listed

CISA SSVCTrack at every mission impact level.

An upstream fix is merged but not yet in a tagged release. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines until it ships, then apply the release.

Exploitation none (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact partial (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table

Published

October 2, 2026

Last Modified

October 2, 2026

Advisory Details (7)

Auto-updated Oct 2, 2026
Upstream fix merged — awaiting tagged release. Sources: github_commit.
github_commit

commit 480d878aa6f7 (bcgit/bc-java)

Fix landed in bcgit/bc-java commit 480d878aa6f7 — awaiting tagged release

https://github.com/bcgit/bc-java/commit/480d878aa6f7dc8b20403064f304bbe0decbbb1a
github_commit

commit e72bc0681ff4 (bcgit/bc-java)

Fix landed in bcgit/bc-java commit e72bc0681ff4 — awaiting tagged release

https://github.com/bcgit/bc-java/commit/e72bc0681ff4227fced912ef7394daf7b7d57bb3
github_commit

commit 766a31026ac2 (bcgit/bc-java)

Fix landed in bcgit/bc-java commit 766a31026ac2 — awaiting tagged release

https://github.com/bcgit/bc-java/commit/766a31026ac24ed3c6cad8662058ba450c338da1
github_commit

commit 20ed9e203cae (bcgit/bc-java)

Fix landed in bcgit/bc-java commit 20ed9e203cae — awaiting tagged release

https://github.com/bcgit/bc-java/commit/20ed9e203caec91d25cd386ceb6d364e9b068f67
github_commit

commit 442393bf187c (bcgit/bc-java)

Fix landed in bcgit/bc-java commit 442393bf187c — awaiting tagged release

https://github.com/bcgit/bc-java/commit/442393bf187c914b1e66fbed4fab532a1fe06c6a
github_commit

commit 882fdab53f6c (bcgit/bc-java)

Fix landed in bcgit/bc-java commit 882fdab53f6c — awaiting tagged release

https://github.com/bcgit/bc-java/commit/882fdab53f6c4c150a5d6a4e6ef1fc05d382385a
generic

CVE‐2026‐17508 · bcgit/bc-java Wiki · GitHub

https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9017508

Vendor Advisories for CVE-2026-17508(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 13× in last 7d / 13× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-10-03 19:06 UTCEG score recompute
  2. 2026-10-03 19:06 UTCGHSA enrichment
  3. 2026-10-03 14:25 UTCEPSS rescore
  4. 2026-10-02 18:20 UTCGHSA enrichment
  5. 2026-10-02 18:20 UTCEG score recompute
  6. 2026-10-02 18:20 UTCGHSA enrichment
  7. 2026-10-02 18:20 UTCGHSA enrichment
  8. 2026-10-02 17:47 UTCEG score recompute
  9. 2026-10-02 17:47 UTCGHSA enrichment
  10. 2026-10-02 14:45 UTCGHSA enrichment
  11. 2026-10-02 08:27 UTCEG score recompute
  12. 2026-10-02 07:47 UTCEG score recompute
  13. 2026-10-02 07:45 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-17508?
CVE-2026-17508 is a medium vulnerability published on October 2, 2026. In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an arbitrary amount of work before any password or integrity check could…
When was CVE-2026-17508 disclosed?
CVE-2026-17508 was first published on October 2, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-17508 actively exploited?
CVE-2026-17508 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0.4% probability of exploitation in the next 30 days (35th percentile of EPSS-scored CVEs).
What is the CVSS score of CVE-2026-17508?
CVE-2026-17508 has a CVSS base score of 5.3 (a secondary CVSS source that NVD displays; NVD's own analysis pending).
How do I remediate CVE-2026-17508?
An upstream fix for CVE-2026-17508 has been merged but is not yet in a tagged release. Until it ships, restrict network exposure of the affected system or apply the vendor's mitigation, then update to the release that contains the fix. The vendor advisories EchelonGraph has for CVE-2026-17508 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-17508

Explore →

Is Your Infrastructure Affected by CVE-2026-17508?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.