CVE-2026-58060 Details
Description
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
A vulnerability exists in Bouncy Castle for Java in versions prior to 1.85, as well as in the LTS versions prior to 2.73.12 and in the FIPS versions prior to 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series). The issue arises from HSS public-key level counts not being properly bounded, which can lead to excessive memory allocation during the verification process. This vulnerability allows for the possibility of denial-of-service attacks by causing large allocations of resources.
Users can upgrade to Bouncy Castle for Java version 1.85 or later, or to version 2.73.12 or later in the LTS series. For those using Bouncy Castle FIPS, version 2.0.2 (2.0.X series) or 2.1.3 (2.1.X series) should be used.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276 | bcorg | Patch |
| https://github.com/bcgit/bc-java/commit/6c9f30b3fdaa3f2140809278caebbffc55920922 | bcorg | Patch |
| https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058060 | bcorg | Third Party AdvisoryPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-789 | Memory Allocation with Excessive Size Value | bcorg |
Affected Products
| Product | Versions |
|---|---|
| bouncycastle bc-java | >= 1.65, < 1.85 |
CPE
Remediation
| |
| bouncycastle bouncy castle for java lts | <= 2.73.11 |
CPE
Remediation
| |
| bouncycastle fips java api | < 2.0.2 >= 2.1.0, < 2.1.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 2, 2026 | Initial Analysis | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | CVE Modified | bcorg |
| Aug 3, 2026 | New CVE Received | bcorg |