What is CVE-2026-59638?
CVE-2026-59638 involves a vulnerability in Bouncy Castle for Java where the JSSE hostname verifier CN-fallback is enabled by default, contrary to documented opt-in requirements. This affects versions before 1.85, as well as specific LTS and FIPS releases, potentially allowing verification bypass. Updating to the fixed versions is strongly recommended.
Azərbaycanca: CVE-2026-59638 Bouncy Castle Java kitabxanasında JSSE hostname verifier-in default olaraq aktiv olan CN-fallback funksiyası ilə bağlıdır. Bu zəiflik sənədləşdirilmiş opt-in tələbinə baxmayaraq default aktiv olduğu üçün təsdiqləmə mexanizmini yan keçməyə imkan verir. Bu problem 1.85-dən əvvəlki versiyalar, eləcə də müəyyən LTS və FIPS versiyaları da daxil olmaqla bir çox sistemləri təsir edir, dərhal müvafiq yamaların tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
What library does CVE-2026-59638 affect and what is the root cause?
This vulnerability affects the Bouncy Castle Java library. The root cause is that the CN-fallback function in the JSSE hostname verifier is enabled by default, contrary to the documented opt-in requirement.
Which versions should be updated to protect against CVE-2026-59638?
It is strongly recommended to immediately apply the relevant patches for versions before 1.85, as well as for the affected specific LTS and FIPS releases.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.