StackRadar

CVE-2025-8885

Medium

Advisory

Published 12 Aug 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
77
of 17,781 indexed, latest versions
Container images
75
deployed by those charts
Fix available
4 of 5
affected packages

Bouncy Castle for Java on All (API modules) allows Excessive Allocation

Carried by container images the latest versions of 77 of 17,781 indexed charts deploy, on 75 images.

Affected packageAffected versionsFixed inImages
bcprov-jdk18onmaven1.71, 1.72, 1.73, 1.74+3 more1.7840
bc-fipsmaven1.0.1, 1.0.2, 1.0.2.1, 1.0.2.3+3 more1.0.2.6, 2.0.133
bcprov-jdk15to18maven1.63, 1.65, 1.70, 1.72+3 more1.7813
bctls-jdk18onmaven1.711.781
bouncycastledeb1.61-1no fix listed1
OSV records
GHSA-67mf-3cr5-8w23UBUNTU-CVE-2025-8885

Charts affected

77 by stars
ChartLatestAffected imagesRadar Score
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
bcprov-jdk15to18@1.72
bcprov-jdk18on@1.71
1.78
1.78

Open the chart page →

7,144
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
bcprov-jdk15to18@1.72
bcprov-jdk18on@1.71
1.78
1.78

Open the chart page →

7,862
fpga-operatorinaccelVerified publisher2.8.21 of 7See more

fpga-operator inaccel 2.8.2

1 of the 7 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
bcprov-jdk18on@1.77
1.78

Open the chart page →

5,759
daveit-at-mOfficialVerified publisher0.2.151 of 11See more

dave it-at-m 0.2.15

1 of the 11 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
bc-fips@1.0.2.5
1.0.2.6

Open the chart page →

15,089
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
bcprov-jdk15to18@1.65
1.78

Open the chart page →

12,856
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
bcprov-jdk18on@1.77
1.78

Open the chart page →

5,759
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
bc-fips@1.0.1
1.0.2.6

Open the chart page →

7,929
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
bc-fips@1.0.2.5
1.0.2.6

Open the chart page →

4,257
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
bcprov-jdk18on@1.76
1.78

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
bcprov-jdk18on@1.73
1.78

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
bcprov-jdk18on@1.73
1.78

Open the chart page →

4,599
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
bc-fips@1.0.2
1.0.2.6

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
bc-fips@1.0.2
1.0.2.6

Open the chart page →

10,603
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
bc-fips@1.0.2
1.0.2.6

Open the chart page →

9,300
datawolfncsaVerified publisher1.1.01 of 3See more

datawolf ncsa 1.1.0

1 of the 3 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
ncsa/datawolf:4.7.0af6649d59150
bcprov-jdk18on@1.72
1.78

Open the chart page →

4,989
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
bcprov-jdk18on@1.77
1.78

Open the chart page →

15,369
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
bcprov-jdk18on@1.77
1.78

Open the chart page →

5,826
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
bcprov-jdk18on@1.75
1.78

Open the chart page →

9,005
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
bcprov-jdk18on@1.74
1.78

Open the chart page →

6,037
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
bc-fips@1.0.2.4
bcprov-jdk15to18@1.76
bcprov-jdk18on@1.77
1.0.2.6
1.78
1.78

Open the chart page →

1,190
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
bc-fips@2.0.0
2.0.1

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
bc-fips@1.0.2.5
bcprov-jdk15to18@1.75
1.0.2.6
1.78

Open the chart page →

1,753
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
bc-fips@1.0.2.4
bcprov-jdk18on@1.77
1.0.2.6
1.78

Open the chart page →

5,269
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
bc-fips@1.0.2.4
bcprov-jdk18on@1.76
1.0.2.6
1.78

Open the chart page →

4,203
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
bcprov-jdk15to18@1.75
1.78

Open the chart page →

4,946
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
bc-fips@1.0.2
1.0.2.6

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
bc-fips@2.0.0
2.0.1

Open the chart page →

9,381

Container images carrying it

75 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
bcprov-jdk18on@1.77
1.78
1
opensearchproject/data-prepper:2.8.057c25fa01d3c
bcprov-jdk18on@1.76
1.78
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
bcprov-jdk18on@1.71
bctls-jdk18on@1.71
1.78
1.78
1
opensearchproject/opensearch:2.15.01963b3ece46d
bc-fips@1.0.2.5
bcprov-jdk15to18@1.74
1.0.2.6
1.78
1
opensearchproject/opensearch:2.14.0466a49f379bb
bc-fips@1.0.2.5
bcprov-jdk15to18@1.75
1.0.2.6
1.78
1
opensearchproject/opensearch:3.1.0474ea3fdf25d
bc-fips@2.0.0
2.0.1
1
opensearchproject/opensearch:2.12.0645d3d9390ad
bc-fips@1.0.2.4
bcprov-jdk15to18@1.76
bcprov-jdk18on@1.77
1.0.2.6
1.78
1.78
1
opensearchproject/opensearch:2.19.269588c664014
bc-fips@2.0.0
2.0.1
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
bc-fips@1.0.2.3
bcprov-jdk15to18@1.75
1.0.2.6
1.78
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
bcprov-jdk18on@1.71
1.78
1
sonatype/nexus3:3.58.1586060431b64
bcprov-jdk15to18@1.75
1.78
1
treskon/portrait:DEV-latest88e813f22347
bcprov-jdk18on@1.76
1.78
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
bc-fips@1.0.2.5
1.0.2.6
1
wistefan/mvf:lateste0887302b2d8
bcprov-jdk15to18@1.72
bcprov-jdk18on@1.71
1.78
1.78
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
bc-fips@1.0.2
1.0.2.6
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
bc-fips@1.0.2
1.0.2.6
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
bcprov-jdk15to18@1.65
1.78
1
ghcr.io/komputing/fauceth:release4ab8fa4143b4
bcprov-jdk15to18@1.70
1.78
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
bcprov-jdk18on@1.71
1.78
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
bcprov-jdk15to18@1.72
bcprov-jdk18on@1.71
1.78
1.78
1
quay.io/keycloak/keycloak:24.0.34d6f22991266
bcprov-jdk18on@1.77
1.78
1
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
bcprov-jdk18on@1.74
1.78
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
bcprov-jdk18on@1.74
1.78
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
bcprov-jdk18on@1.74
1.78
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
bcprov-jdk18on@1.74
1.78
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.