In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
References
| Link | Resource |
|---|---|
| https://github.com/bcgit/bc-java/commit/99ddc6dcc6782e6a76b0dd587c77e62eb7096ad0 | Patch |
| https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059639 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-03 01:16
Updated : 2026-08-28 15:33
NVD link : CVE-2026-59639
Mitre link : CVE-2026-59639
CVE.ORG link : CVE-2026-59639
JSON object : View
Products Affected
bouncycastle
- bouncy_castle_for_java_lts
- bcpkix-fips
- bc-java
CWE
CWE-347
Improper Verification of Cryptographic Signature
