A vulnerability was found in Legion of the Bouncy Castle Bouncy Castle for Java FIPS, Bouncy Castle for Java LTS and Bouncy Castle for Java up to 1.84/2.73.11/2.0.6/2.1.6. It has been declared as problematic. This affects an unknown function of the component OER parser. Executing a manipulation can lead to resource consumption.

This vulnerability is handled as CVE-2026-59645. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.