What is CVE-2026-59643?
CVE-2026-59643 is a vulnerability in Bouncy Castle for Java where OpenPGP inline-signature policy failures are silently ignored. It affects versions before 1.85 and BC-FJA before bcpg-fips 2.0.13, requiring immediate update to the patched versions.
Azərbaycanca: CVE-2026-59643 Bouncy Castle Java kitabxanasında OpenPGP inline-imza siyasəti uğursuzluqlarının səssizcə görməzdən gəlinməsinə səbəb olan zəiflikdir. Bu, 1.85-dən əvvəlki versiyalar və BC-FJA bcpg-fips 2.0.13-dən əvvəlki versiyalara təsir edir, istifadəçilərə dərhal yeniləmə tövsiyə olunur.
FAQ2
What functional area does CVE-2026-59643 affect in the Bouncy Castle library?
This vulnerability affects the OpenPGP inline-signature policy handling in Bouncy Castle for Java, where policy failures are silently ignored.
Which versions should be updated to remediate CVE-2026-59643?
Users should update to Bouncy Castle version 1.85, or BC-FJA bcpg-fips version 2.0.13, to remediate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.