CVE-2026-59642
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
Summary
In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 0 < 1.85 | affected |
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 < 2.73.12 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.0 < 1.0.12 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 2.0.0 < 2.0.12 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 2.1.0 < 2.1.12 | affected |
Weaknesses
- CWE-354: CWE-354 Improper Validation of Integrity Check Value
References
- https://github.com/bcgit/bc-java/wiki/CVE-2026-59642
- https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.