What is CVE-2026-58061?
In Bouncy Castle for Java, the CCM-family cipher modes write plaintext to the caller's buffer before completing the authentication tag check. This affects versions prior to 1.85, as well as associated LTS and FIPS (BC-FJA) releases. Users should immediately apply the available security patches.
Azərbaycanca: Bouncy Castle kitabxanasında CCM şifrələmə rejimi, autentifikasiya teqini yoxlamadan əvvəl şifrələnmiş mətni çağırıcının buferinə yazır. Bu boşluq Java üçün Bouncy Castle-in 1.85-dən əvvəlki versiyalarına, eləcə də müvafiq LTS, FIPS və BC-FJA buraxılışlarına təsir edir. İstifadəçilərə dərhal təhlükəsizlik yeniləmələrini tətbiq etmələri tövsiyə olunur.
FAQ1
Which cryptographic mode in Bouncy Castle is affected by CVE-2026-58061?
This vulnerability affects CCM-family cipher modes, where plaintext is written to the caller's buffer before the authentication tag check is completed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.