CVE-2026-59648
published 2026-08-03CVE-2026-59648: In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.27%
19.6th percentile
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bcpg-fips | >= 1.0.6 < 1.0.13 | 1.0.13 |
| bouncycastle | bcpg-fips | >= 2.0.8 < 2.0.13 | 2.0.13 |
| bouncycastle | bcpg-fips | >= 2.1.10 < 2.1.13 | 2.1.13 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.6 < 1.0.13 | 1.0.13 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.13 | 2.0.13 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.13 | 2.1.13 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.71 < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java resource consumption
vuldb·2026-08-03·CVSS 6.9
CVE-2026-59648 [MEDIUM] Legion of the Bouncy Castle Bouncy Castle for Java resource consumption
A vulnerability described as problematic has been identified in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS. This vulnerability affects unknown code. Executing a manipulation can lead to resource consumption.
This vulnerability is tracked as CVE-2026-59648. The attack can be launched remotely. No exploit exists.
GHSA
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes.
ghsa_unreviewed·2026-08-03
CVE-2026-59648 [MEDIUM] CWE-770 In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes.
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Red Hat
org.bouncycastle/bcpg-jdk15on: org.bouncycastle/bcpg-fips: Bouncy Castle for Java: Denial of Service via attacker-chosen memory in OpenPGP Argon2 S2K
vendor_redhat·2026-08-03·CVSS 6.9
CVE-2026-59648 [MEDIUM] CWE-770 org.bouncycastle/bcpg-jdk15on: org.bouncycastle/bcpg-fips: Bouncy Castle for Java: Denial of Service via attacker-chosen memory in OpenPGP Argon2 S2K
org.bouncycastle/bcpg-jdk15on: org.bouncycastle/bcpg-fips: Bouncy Castle for Java: Denial of Service via attacker-chosen memory in OpenPGP Argon2 S2K
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
A flaw was found in Bouncy Castle for Java. The OpenPGP Argon2 S2K (Salted Key Derivation Function) implementation allows a remote attacker to influence the amount of memory and passes used during key derivation. This can lead to a denial of service (DoS) by consuming excessive system resources, making the application unavailable to legitimate user
No detection rules found.
No public exploits indexed.
2026-08-03
Published