What is CVE-2026-58059?
A quadratic-time escaping vulnerability was discovered in Bouncy Castle for Java when processing X.500 Distinguished Names, potentially leading to excessive resource consumption. This issue impacts multiple versions, and users are advised to upgrade to the patched releases mentioned in the advisory.
Azərbaycanca: Bouncy Castle for Java kitabxanasında X.500 fərqləndirici adlarını (Distinguished Names) emal edərkən quadratic-time escaping səbəbindən performans zəifliyi aşkarlanıb. Bu, sistem resurslarının həddindən artıq istehlakına səbəb ola bilər. Təsirə məruz qalan versiyaları işlədən istifadəçilər göstərilən yeni versiyalara yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Bouncy Castle
FAQ2
During which operation does the CVE-2026-58059 vulnerability occur in the Bouncy Castle for Java library?
This vulnerability occurs due to quadratic-time escaping when processing X.500 Distinguished Names.
What impact can CVE-2026-58059 have on the system?
It can lead to excessive resource consumption.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.