CVE-2026-59639
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
Summary
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 0 < 1.85 | affected |
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 < 2.73.12 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.0 < 1.0.12 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 2.0.0 < 2.0.12 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 2.1.0 < 2.1.12 | affected |
Weaknesses
- CWE-347: CWE-347 Improper Verification of Cryptographic Signature
References
- https://github.com/bcgit/bc-java/wiki/CVE-2026-59639
- https://github.com/bcgit/bc-java/commit/99ddc6dcc6782e6a76b0dd587c77e62eb7096ad0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.