← All Advisories

Bouncy Castle Java G3413CTRBlockCipher Implements CTR Mode Incorrectly, Silently Weakening Encryption for Network-Accessible Applications

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2025-14813

Key Details

CVECVE-2025-14813
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productssee table below
Classified asCWE-327 (Use of a Broken or Risky Cryptographic Algorithm)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat OpenShift AI 2.25
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9
Red HatRed Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
Red HatRed Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
Red HatRed Hat Single Sign-On 7
Red HatRed Hat build of Apache Camel 4 for Quarkus 3
Red HatRed Hat build of Debezium 3
Red HatRed Hat JBoss Enterprise Application Platform 8
Red HatRed Hat Build of Keycloak
Red HatRed Hat Process Automation 7
Red HatRed Hat AMQ Clients
Red HatRed Hat Fuse 7
Red HatRed Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14
Red HatRed Hat JBoss Enterprise Application Platform 8.1.7.GA
Red HatOpenShift Developer Tools and Services 4.12
Red HatOpenShift Developer Tools and Services 4.13
Red HatOpenShift Developer Tools and Services 4.14
Red HatOpenShift Developer Tools and Services 4.15
Red HatOpenShift Developer Tools and Services 4.16
Red HatOpenShift Developer Tools and Services 4.17
Red HatOpenShift Developer Tools and Services 4.18
Red HatOpenShift Developer Tools and Services 4.19
Red HatOpenShift Developer Tools and Services 4.20
Red HatOpenShift Developer Tools and Services 4.21
Red HatOpenShift Developer Tools and Services 4.22
Red HatRed Hat OpenShift Dev Spaces 3.28
Red HatOpenShift Developer Tools and Services
Red Hatstreams for Apache Kafka 2
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).

This vulnerability is associated with program files G3413CTRBlockCipher.

This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-14813
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-14813