What is CVE-2026-59641?
CVE-2026-59641 is a vulnerability in Bouncy Castle's S/MIME validator where it trusts the signer-asserted 'signingTime' for path validation. This affects multiple versions. Developers should update to the fixed versions.
Azərbaycanca: CVE-2026-59641 Bouncy Castle kitabxanasının S/MIME validatorunda zəiflikdir: o, sertifikat yolunun yoxlanması zamanı imzalayanın iddia etdiyi 'signingTime' atributuna kor-koranə etibar edir. Bu, müxtəlif versiyalara təsir edir. Tərtibatçılar göstərilən versiyalara yeniləmə aparmalıdırlar.
Related CVEs
link basis: shared vendor: Bouncy Castle
FAQ2
What is CVE-2026-59641 and what issue does it cause in Bouncy Castle's S/MIME validation?
CVE-2026-59641 is a vulnerability in the Bouncy Castle library's S/MIME validator. This issue arises because it blindly trusts the signer-asserted 'signingTime' attribute during certificate path validation.
What should developers do to mitigate the CVE-2026-59641 vulnerability?
Developers should update the affected versions of the Bouncy Castle library to the fixed versions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.