CVE-2026-59640 Details
Description
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
A vulnerability exists in Bouncy Castle for Java in versions prior to 1.85, as well as in the LTS version prior to 2.73.12 and in the FIPS versions BC-FJA prior to 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series). This vulnerability introduces an active oracle on the CFB 'quick check' bytes during decryption, specifically on the symmetric and session-key paths. The issue allows an attacker with a decryption oracle to distinguish between ciphertexts and potentially recover plaintext.
Users can upgrade to Bouncy Castle for Java version 1.85 or later, or to version 2.73.12 or later for the LTS release. For the FIPS versions, upgrade to bcpg-fips 1.0.13, 2.0.13 or 2.1.13.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bcgit/bc-java/commit/6b94b1c146cec1f565d9a85847fae511af77503e | bcorg | Patch |
| https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059640 | bcorg | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-203 | Observable Discrepancy | bcorg |
Affected Products
| Product | Versions |
|---|---|
| bouncycastle bc-java | < 1.85 |
CPE
Remediation
| |
| bouncycastle bcpg-fips | < 1.0.13 >= 2.0.8, < 2.0.13 >= 2.1.10, < 2.1.13 |
CPE
Remediation
| |
| bouncycastle bouncy castle for java lts | <= 2.73.11 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 28, 2026 | Initial Analysis | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | CVE Modified | bcorg |
| Aug 3, 2026 | New CVE Received | bcorg |