What is CVE-2026-59642?
In Bouncy Castle, CMS AuthenticatedData content is not properly bound to the MAC when authAttrs are present. This vulnerability affects Bouncy Castle for Java before version 1.85. Immediate update to the fixed versions is recommended.
Azərbaycanca: Bouncy Castle kitabxanasında CMS AuthenticatedData strukturunda authAttrs olduqda məzmun MAC-ə düzgün bağlanmır. Bu boşluq Bouncy Castle Java 1.85-dən əvvəlki versiyalara təsir edir. Dərhal müvafiq versiyalara yenilənmə tövsiyə olunur.
Related CVEs
link basis: shared vendor: Bouncy Castle
FAQ2
Which versions of Bouncy Castle are affected by CVE-2026-59642?
This vulnerability affects Bouncy Castle for Java before version 1.85.
When does the MAC binding issue in CVE-2026-59642 occur?
The content is not properly bound to the MAC when authAttrs are present in the CMS AuthenticatedData structure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.