CVE-2026-59643
published 2026-08-03CVE-2026-59643: In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA)…
PriorityP345high8.7CVSS 4.0
AVNACLATNPRNUINVCNVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUAmber
EPSS
0.18%
8.0th percentile
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.12 < 2.0.13 | 2.0.13 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.81 < 1.85 | 1.85 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java/Bouncy Castle for Java FIPS OpenPGP protection mechanism
vuldb·2026-08-03·CVSS 8.7
CVE-2026-59643 [HIGH] Legion of the Bouncy Castle Bouncy Castle for Java/Bouncy Castle for Java FIPS OpenPGP protection mechanism
A vulnerability, which was classified as critical, was found in Legion of the Bouncy Castle Bouncy Castle for Java and Bouncy Castle for Java FIPS. The impacted element is an unknown function of the component OpenPGP. Such manipulation leads to protection mechanism failure.
This vulnerability is documented as CVE-2026-59643. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored.
ghsa_unreviewed·2026-08-03
CVE-2026-59643 [HIGH] CWE-347 In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored.
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-03
Published