CVE-2026-59639
Last modified
CVE-2026-59639 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | < 1.85 |
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | >= 2.73.0, < 2.73.12 |
| Legion of the Bouncy Castle Inc. | BC-FJA | >= 1.0.0, < 1.0.12; >= 2.0.0, < 2.0.12; >= 2.1.0, < 2.1.12 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-59639?
How severe is CVE-2026-59639?
How do I fix CVE-2026-59639?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5959A security flaw has been discovered in GL.iNet GL-RM1, GL-RM…7.5
- CVE-2026-5960A weakness has been identified in code-projects Patient Reco…4.3
- CVE-2026-5961A security vulnerability has been detected in code-projects …7.3
- CVE-2026-5962A vulnerability was detected in Tenda CH22 1.0.0.6(468). Thi…9.8
- CVE-2026-5963EasyFlow .NET developed by Digiwin has a SQL Injection vulne…9.8
- CVE-2026-59638In Bouncy Castle for Java before 1.85, JSSE hostname verifie…9.3
- CVE-2026-5964EasyFlow .NET developed by Digiwin has a SQL Injection vulne…9.8
- CVE-2026-59640In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-che…8.7
- CVE-2026-59641In Bouncy Castle for Java before 1.85, S/MIME validator trus…8.7
- CVE-2026-59642In Bouncy Castle for Java before 1.85, CMS AuthenticatedData…8.7
- CVE-2026-59643In Bouncy Castle for Java before 1.85, OpenPGP inline-signat…8.7
- CVE-2026-59644In Bouncy Castle for Java before 1.85, MLS hash-ratchet hono…8.7
Are you affected by CVE-2026-59639?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
