What is CVE-2026-59640?
A vulnerability in Bouncy Castle for Java before version 1.85 involves an active OpenPGP CFB quick-check oracle on symmetric/session-key paths. This affects LTS, FIPS, and standard editions, allowing potential attacks on key validation. Users must update to the specified patched versions immediately.
Azərbaycanca: Bouncy Castle for Java kitabxanasının 1.85-dən əvvəlki versiyalarında OpenPGP CFB quick-check oracle zəifliyi aşkarlanıb. Bu, simmetrik açar yolları üzərində aktiv oracle hücumlarına imkan verir. Təsirə məruz qalan LTS, FIPS versiyaları daxil bütün istifadəçilər dərhal qeyd olunan yamaqlanmış versiyalara yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Bouncy Castle for Java are affected by CVE-2026-59640?
Versions of Bouncy Castle for Java before 1.85, including LTS, FIPS, and standard editions, are affected.
What type of attack does CVE-2026-59640 enable?
This vulnerability enables active oracle attacks on symmetric key paths via the OpenPGP CFB quick-check oracle.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.