CVE-2026-59644

Summary

In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.

Affected Software

VendorProductVersion RangeStatus
Legion of the Bouncy Castle Inc.BC-JAVA1.73 < 1.85affected

Weaknesses

  • CWE-834: CWE-834 Excessive Iteration

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References