CVE-2026-59640
published 2026-08-03CVE-2026-59640: In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.22%
12.0th percentile
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bcpg-fips | < 1.0.13 | 1.0.13 |
| bouncycastle | bcpg-fips | >= 2.0.8 < 2.0.13 | 2.0.13 |
| bouncycastle | bcpg-fips | >= 2.1.10 < 2.1.13 | 2.1.13 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.0 < 1.0.13 | 1.0.13 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.13 | 2.0.13 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.13 | 2.1.13 |
| legion_of_the_bouncy_castle_inc | bc-java | < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths.
ghsa_unreviewed·2026-08-03
CVE-2026-59640 [HIGH] CWE-203 In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths.
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java up to 2.1.12 OpenPGP security check
vuldb·2026-08-03·CVSS 8.7
CVE-2026-59640 [HIGH] Legion of the Bouncy Castle Bouncy Castle for Java up to 2.1.12 OpenPGP security check
A vulnerability was found in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS up to 1.84/2.73.11/1.0.12/2.0.12/2.1.12. It has been classified as critical. The impacted element is an unknown function of the component OpenPGP. Performing a manipulation results in security check for standard.
This vulnerability is known as CVE-2026-59640. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
Red Hat
org.bouncycastle/bcpg-jdk15on: org.bouncycastle/bcpg-fips: Bouncy Castle for Java: Information disclosure via OpenPGP CFB quick-check oracle
vendor_redhat·2026-08-03·CVSS 8.7
CVE-2026-59640 [HIGH] CWE-208 org.bouncycastle/bcpg-jdk15on: org.bouncycastle/bcpg-fips: Bouncy Castle for Java: Information disclosure via OpenPGP CFB quick-check oracle
org.bouncycastle/bcpg-jdk15on: org.bouncycastle/bcpg-fips: Bouncy Castle for Java: Information disclosure via OpenPGP CFB quick-check oracle
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
A flaw was found in Bouncy Castle for Java. A remote attacker can exploit an OpenPGP (Open Pretty Good Privacy) Cipher Feedback (CFB) quick-check oracle vulnerability. This oracle, active on symmetric and session-key paths, could allow an attacker to gain sensitive information by observing the results of cryptographic operations. This could lead to
No detection rules found.
No public exploits indexed.
2026-08-03
Published