Status: UPDATED | Advisory ID: CVE-2025-14813
| CVE | CVE-2025-14813 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-10-07 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | see table below |
| Classified as | CWE-327 (Use of a Broken or Risky Cryptographic Algorithm) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift AI (RHOAI) | ||
| Red Hat | Red Hat OpenShift AI 2.25 | ||
| Red Hat | Red Hat Enterprise Linux 8 | ||
| Red Hat | Red Hat Enterprise Linux 9 | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8 | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9 | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | ||
| Red Hat | Red Hat Single Sign-On 7 | ||
| Red Hat | Red Hat build of Apache Camel 4 for Quarkus 3 | ||
| Red Hat | Red Hat build of Debezium 3 | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | ||
| Red Hat | Red Hat Build of Keycloak | ||
| Red Hat | Red Hat Process Automation 7 | ||
| Red Hat | Red Hat AMQ Clients | ||
| Red Hat | Red Hat Fuse 7 | ||
| Red Hat | Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1.7.GA | ||
| Red Hat | OpenShift Developer Tools and Services 4.12 | ||
| Red Hat | OpenShift Developer Tools and Services 4.13 | ||
| Red Hat | OpenShift Developer Tools and Services 4.14 | ||
| Red Hat | OpenShift Developer Tools and Services 4.15 | ||
| Red Hat | OpenShift Developer Tools and Services 4.16 | ||
| Red Hat | OpenShift Developer Tools and Services 4.17 | ||
| Red Hat | OpenShift Developer Tools and Services 4.18 | ||
| Red Hat | OpenShift Developer Tools and Services 4.19 | ||
| Red Hat | OpenShift Developer Tools and Services 4.20 | ||
| Red Hat | OpenShift Developer Tools and Services 4.21 | ||
| Red Hat | OpenShift Developer Tools and Services 4.22 | ||
| Red Hat | Red Hat OpenShift Dev Spaces 3.28 | ||
| Red Hat | OpenShift Developer Tools and Services | ||
| Red Hat | streams for Apache Kafka 2 |
| Subsystems | OT Supporting Infrastructure |
| Sectors | Multiple |
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).
This vulnerability is associated with program files G3413CTRBlockCipher.
This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84. (NVD)
Monitor Red Hat's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2025-14813 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2025-14813 |