CVE-2026-59643 Details
Description
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.
A vulnerability exists in Bouncy Castle for Java versions prior to 1.85 and in Bouncy Castle for Java FIPS (BC-FJA) prior to bcpg-fips 2.0.13. This vulnerability arises from the OpenPGP inline-signature verification process, which fails to properly enforce signature policies. As a result, signatures that should be rejected based on policy criteria are incorrectly reported as valid. The issue stems from the verification method catching policy-related exceptions but failing to act on them, allowing policy-rejected signatures to be misrepresented as correct.
Users can upgrade to Bouncy Castle for Java version 1.85 or later, or to Bouncy Castle for Java FIPS version bcpg-fips 2.0.13 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bcgit/bc-java/commit/d3f8cc408b4a36d28e5a410c93436fe3d0fe726b | bcorg | Patch |
| https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059643 | bcorg | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | bcorg |
Affected Products
| Product | Versions |
|---|---|
| bouncycastle bc-java | < 1.85 |
CPE
Remediation
| |
| bouncycastle bcpg-fips | < 2.0.13 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | Initial Analysis | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | CVE Modified | bcorg |
| Aug 3, 2026 | New CVE Received | bcorg |