What is CVE-2026-58060?
In Bouncy Castle for Java, the HSS public-key level count is unbounded, allowing an attacker to trigger huge memory allocations during signature verification. This affects versions before 1.85, LTS before 2.73.12, and specific FIPS releases. Users must update to patched versions immediately.
Azərbaycanca: Bouncy Castle for Java kitabxanasında boşluq — HSS açıq açarının səviyyə sayı sərhədsiz olduğu üçün, doğrulama zamanı həddindən artıq yaddaş ayrılması baş verə bilər. Bu, 1.85-dən əvvəlki Bouncy Castle for Java, 2.73.12-dən əvvəlki LTS, eləcə də müəyyən FIPS versiyalarına təsir edir. Tərtibatçılar dərhal təhlükəsizlik yeniləmələrini tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
Which versions of Bouncy Castle for Java are affected by CVE-2026-58060?
This vulnerability affects Bouncy Castle for Java before 1.85, LTS before 2.73.12, and specific FIPS releases.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.