CVE-2026-59641 Details
Description
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
A vulnerability exists in Bouncy Castle for Java in versions prior to 1.85, as well as in the LTS version prior to 2.73.12 and in Bouncy Castle for Java FIPS (BC-FJA) versions prior to 1.0.7, 2.0.7 and 2.1.7. The issue arises because the S/MIME validator improperly trusts the signer-asserted signingTime for certificate path validation. This can lead to incorrect evaluations of certificate expiry and revocation, allowing signatures to be validated based on a back-dated signing time that does not reflect the actual status of the signing certificate.
Users can upgrade to Bouncy Castle for Java version 1.85 or later, or to version 2.73.12 or later for the LTS version. For Bouncy Castle FIPS users, version 1.0.7, 2.0.7 or 2.1.7 should be used.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bcgit/bc-java/commit/2f81b22d559b3a1b026388e1ca78dd547384def8 | bcorg | Patch |
| https://github.com/bcgit/bc-java/commit/fd89fe918b37fea1c71e95fae50284a325b09721 | bcorg | Patch |
| https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059641 | bcorg | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | bcorg |
Affected Products
| Product | Versions |
|---|---|
| bouncycastle bc-java | < 1.85 |
CPE
Remediation
| |
| bouncycastle bcjmail-fips | < 1.0.7 >= 2.0.5, < 2.0.7 >= 2.1.6, < 2.1.7 |
CPE
Remediation
| |
| bouncycastle bcmail-fips | < 1.0.7 >= 2.0.5, < 2.0.7 >= 2.1.6, < 2.1.7 |
CPE
Remediation
| |
| bouncycastle bouncy castle for java lts | <= 2.73.11 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 28, 2026 | Initial Analysis | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | CVE Modified | bcorg |
| Aug 3, 2026 | New CVE Received | bcorg |