StackRadar

CVE-2025-8885

Medium

Advisory

Published 12 Aug 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
77
of 17,781 indexed, latest versions
Container images
75
deployed by those charts
Fix available
4 of 5
affected packages

Bouncy Castle for Java on All (API modules) allows Excessive Allocation

Carried by container images the latest versions of 77 of 17,781 indexed charts deploy, on 75 images.

Affected packageAffected versionsFixed inImages
bcprov-jdk18onmaven1.71, 1.72, 1.73, 1.74+3 more1.7840
bc-fipsmaven1.0.1, 1.0.2, 1.0.2.1, 1.0.2.3+3 more1.0.2.6, 2.0.133
bcprov-jdk15to18maven1.63, 1.65, 1.70, 1.72+3 more1.7813
bctls-jdk18onmaven1.711.781
bouncycastledeb1.61-1no fix listed1
OSV records
GHSA-67mf-3cr5-8w23UBUNTU-CVE-2025-8885

Charts affected

77 by stars
ChartLatestAffected imagesRadar Score
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
bcprov-jdk15to18@1.72
bcprov-jdk18on@1.71
1.78
1.78

Open the chart page →

7,144
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
bcprov-jdk15to18@1.72
bcprov-jdk18on@1.71
1.78
1.78

Open the chart page →

7,862
fpga-operatorinaccelVerified publisher2.8.21 of 7See more

fpga-operator inaccel 2.8.2

1 of the 7 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
bcprov-jdk18on@1.77
1.78

Open the chart page →

5,759
daveit-at-mOfficialVerified publisher0.2.151 of 11See more

dave it-at-m 0.2.15

1 of the 11 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
bc-fips@1.0.2.5
1.0.2.6

Open the chart page →

15,089
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
bcprov-jdk15to18@1.65
1.78

Open the chart page →

12,856
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
bcprov-jdk18on@1.77
1.78

Open the chart page →

5,759
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
bc-fips@1.0.1
1.0.2.6

Open the chart page →

7,929
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
bc-fips@1.0.2.5
1.0.2.6

Open the chart page →

4,257
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
bcprov-jdk18on@1.76
1.78

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
bcprov-jdk18on@1.73
1.78

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
bcprov-jdk18on@1.73
1.78

Open the chart page →

4,599
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
bc-fips@1.0.2
1.0.2.6

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
bc-fips@1.0.2
1.0.2.6

Open the chart page →

10,603
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
bc-fips@1.0.2
1.0.2.6

Open the chart page →

9,300
datawolfncsaVerified publisher1.1.01 of 3See more

datawolf ncsa 1.1.0

1 of the 3 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
ncsa/datawolf:4.7.0af6649d59150
bcprov-jdk18on@1.72
1.78

Open the chart page →

4,989
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
bcprov-jdk18on@1.77
1.78

Open the chart page →

15,369
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
bcprov-jdk18on@1.77
1.78

Open the chart page →

5,826
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
bcprov-jdk18on@1.75
1.78

Open the chart page →

9,005
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
bcprov-jdk18on@1.74
1.78

Open the chart page →

6,037
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
bc-fips@1.0.2.4
bcprov-jdk15to18@1.76
bcprov-jdk18on@1.77
1.0.2.6
1.78
1.78

Open the chart page →

1,190
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
bc-fips@2.0.0
2.0.1

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
bc-fips@1.0.2.5
bcprov-jdk15to18@1.75
1.0.2.6
1.78

Open the chart page →

1,753
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
bc-fips@1.0.2.4
bcprov-jdk18on@1.77
1.0.2.6
1.78

Open the chart page →

5,269
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
bc-fips@1.0.2.4
bcprov-jdk18on@1.76
1.0.2.6
1.78

Open the chart page →

4,203
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
bcprov-jdk15to18@1.75
1.78

Open the chart page →

4,946
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
bc-fips@1.0.2
1.0.2.6

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-8885.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
bc-fips@2.0.0
2.0.1

Open the chart page →

9,381

Container images carrying it

75 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
bc-fips@1.0.2
1.0.2.6
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
bc-fips@1.0.2.5
1.0.2.6
2
inaccel/coral:2.18c53744ed70b
bcprov-jdk18on@1.77
1.78
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
bcprov-jdk18on@1.73
1.78
2
library/elasticsearch:7.17.35e6ac15bf6a5
bc-fips@1.0.2
1.0.2.6
2
opensearchproject/opensearch:2.1.04254021a8c71
bc-fips@1.0.2.3
1.0.2.6
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
bc-fips@2.0.0
2.0.1
2
opensearchproject/opensearch:1.1.0967d7f57f72f
bc-fips@1.0.2
1.0.2.6
2
1dev/server:11.9.0cd5b12fe5471
bcprov-jdk18on@1.74
1.78
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
bc-fips@1.0.1
1.0.2.6
1
apache/druid:29.0.10cef139b6bf1
bcprov-jdk18on@1.76
1.78
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
bcprov-jdk18on@1.75
1.78
1
apache/skywalking-oap-server:9.2.0133d35d2c263
bcprov-jdk18on@1.71
1.78
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
bc-fips@1.0.2
1.0.2.6
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
bc-fips@1.0.2
1.0.2.6
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
bc-fips@1.0.2.4
bcprov-jdk18on@1.76
1.0.2.6
1.78
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
bc-fips@1.0.2.4
bcprov-jdk18on@1.76
1.0.2.6
1.78
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
bc-fips@1.0.2.5
1.0.2.6
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
bcprov-jdk18on@1.77
1.78
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
bc-fips@2.0.0
2.0.1
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
bcprov-jdk18on@1.72
1.78
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
bouncycastle@1.61-1
no fix listed
1
camunda/zeebe:8.4.5ab5abc09e407
bcprov-jdk18on@1.77
1.78
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
bc-fips@1.0.2.4
bcprov-jdk18on@1.77
1.0.2.6
1.78
1
drpcorg/dshackle:0.54.08858fae1859d
bcprov-jdk15to18@1.63
1.78
1
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
bcprov-jdk18on@1.77
1.78
1
emeraldpay/dshackle:0.14.0126f0ae0b388
bcprov-jdk15to18@1.63
1.78
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
bcprov-jdk15to18@1.63
1.78
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
bc-fips@1.0.2
1.0.2.6
1
flowable/flowable-rest:7.1.0b7ae287502cd
bcprov-jdk18on@1.77
1.78
1
glasskube/operator:0.12.2be5133100d63
bcprov-jdk15to18@1.76
bcprov-jdk18on@1.74
1.78
1.78
1
gluufederation/opendj:4.3.0_011a1128b28b95
bc-fips@1.0.2.1
1.0.2.6
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
bcprov-jdk18on@1.77
1.78
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
bcprov-jdk18on@1.77
1.78
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
bcprov-jdk18on@1.77
1.78
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
bcprov-jdk18on@1.71
1.78
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
bcprov-jdk18on@1.77
1.78
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
bcprov-jdk18on@1.77
1.78
1
library/elasticsearch:8.17.32cc40b15dff8
bc-fips@1.0.2.5
1.0.2.6
1
library/elasticsearch:8.15.0310b9fc03b06
bc-fips@1.0.2.4
1.0.2.6
1
library/elasticsearch:7.17.0332c6d416808
bc-fips@1.0.2
1.0.2.6
1
library/elasticsearch:7.17.1588c2ec10c7f2
bc-fips@1.0.2
1.0.2.6
1
library/elasticsearch:7.17.8fdc73b3249c1
bc-fips@1.0.2
1.0.2.6
1
library/sonarqube:10.7.0-community0842dcd4c8f8
bc-fips@1.0.2.4
bcprov-jdk18on@1.76
1.0.2.6
1.78
1
library/sonarqube:10.0.0-communityef9723cf4fe4
bc-fips@1.0.2
1.0.2.6
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
bc-fips@1.0.2.3
1.0.2.6
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
bcprov-jdk18on@1.76
1.78
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
bcprov-jdk18on@1.73
1.78
1
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
bcprov-jdk18on@1.73
1.78
1
ncsa/datawolf:4.7.0af6649d59150
bcprov-jdk18on@1.72
1.78
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.