CVE-2026-59641
published 2026-08-03CVE-2026-59641: In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.15%
4.2th percentile
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bcjmail-fips | < 1.0.7 | 1.0.7 |
| bouncycastle | bcjmail-fips | >= 2.0.5 < 2.0.7 | 2.0.7 |
| bouncycastle | bcjmail-fips | >= 2.1.6 < 2.1.7 | 2.1.7 |
| bouncycastle | bcmail-fips | < 1.0.7 | 1.0.7 |
| bouncycastle | bcmail-fips | >= 2.0.5 < 2.0.7 | 2.0.7 |
| bouncycastle | bcmail-fips | >= 2.1.6 < 2.1.7 | 2.1.7 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| jboss-eap-7 | eap74-els-openjdk11-openshift-rhel8 | — | — |
| jboss-eap-7 | eap74-els-openjdk17-openshift-rhel8 | — | — |
| jboss-eap-7 | eap74-els-openjdk8-openshift-rhel8 | — | — |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.0 < 1.0.7 | 1.0.7 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.4 < 1.0.7 | 1.0.7 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.7 | 2.0.7 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.7 | 2.1.7 |
| legion_of_the_bouncy_castle_inc | bc-java | < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java prior 1.85/2.73.12/1.0.7/2.0.7/2.1.7 assertion
vuldb·2026-08-03·CVSS 8.7
CVE-2026-59641 [HIGH] Legion of the Bouncy Castle Bouncy Castle for Java prior 1.85/2.73.12/1.0.7/2.0.7/2.1.7 assertion
A vulnerability identified as critical has been detected in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS. Affected by this vulnerability is an unknown functionality. This manipulation causes reachable assertion.
The identification of this vulnerability is CVE-2026-59641. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation.
ghsa_unreviewed·2026-08-03
CVE-2026-59641 [HIGH] CWE-345 In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation.
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Red Hat
bouncycastle: bcmail-fips: bcjmail-fips: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time
vendor_redhat·2026-08-03·CVSS 5.3
CVE-2026-59641 [MEDIUM] CWE-347 bouncycastle: bcmail-fips: bcjmail-fips: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time
bouncycastle: bcmail-fips: bcjmail-fips: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
A flaw was found in Bouncy Castle for Java. The S/MIME (Secure/Multipurpose Internet Mail Extensions) validator improperly trusts the signing time asserted by the signer during path validation. This could allow an attacker to bypass certificate path validation, potentially leading to the acceptance of invalid or expired certificates. Such
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-59641 bouncycastle: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time [epel-all]
bugzilla·2026-08-27·CVSS 5.3
CVE-2026-59641 [MEDIUM] CVE-2026-59641 bouncycastle: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time [epel-all]
CVE-2026-59641 bouncycastle: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Bugzilla
CVE-2026-59641 bouncycastle: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time [fedora-all]
bugzilla·2026-08-27·CVSS 5.3
CVE-2026-59641 [MEDIUM] CVE-2026-59641 bouncycastle: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time [fedora-all]
CVE-2026-59641 bouncycastle: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Bugzilla
CVE-2026-59641 bouncycastle: bcmail-fips: bcjmail-fips: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time
bugzilla·2026-08-03·CVSS 5.3
CVE-2026-59641 [MEDIUM] CVE-2026-59641 bouncycastle: bcmail-fips: bcjmail-fips: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time
CVE-2026-59641 bouncycastle: bcmail-fips: bcjmail-fips: Bouncy Castle for Java: S/MIME signature validation bypass via signer-asserted signing time
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
2026-08-03
Published