In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
References
| Link | Resource |
|---|---|
| https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7 | Patch |
| https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059642 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-03 01:16
Updated : 2026-08-28 18:12
NVD link : CVE-2026-59642
Mitre link : CVE-2026-59642
CVE.ORG link : CVE-2026-59642
JSON object : View
Products Affected
bouncycastle
- bouncy_castle_for_java_lts
- bcpkix-fips
- bc-java
CWE
CWE-354
Improper Validation of Integrity Check Value
